Skip to content

aws.config.get_conformance_pack_compliance_details

Example SQL Queries

SELECT * FROM
aws.config.get_conformance_pack_compliance_details
WHERE
"conformance_pack_name" = 'VALUE';

Description

Returns compliance details of a conformance pack for all Amazon Web Services resources that are monitered by conformance pack.

Table Definition

Column NameColumn Data Type
conformance_pack_name Required Input Column

Name of the conformance pack.

VARCHAR
filters Input Column

A ConformancePackEvaluationFilters object.

STRUCT(
"config_rule_names" VARCHAR[],
"compliance_type" VARCHAR,
"resource_type" VARCHAR,
"resource_ids" VARCHAR[]
)
Show child fields
filters.compliance_type

Filters the results by compliance.

The allowed values are COMPLIANT and NON_COMPLIANT. INSUFFICIENT_DATA is not supported.

filters.config_rule_names[]
filters.resource_ids[]
filters.resource_type

Filters the results by the resource type (for example, "AWS::EC2::Instance").

limit Input Column

The maximum number of evaluation results returned on each page. If you do no specify a number, Config uses the default. The default is 100.

BIGINT
next_token Input Column

The nextToken string returned in a previous request that you use to request the next page of results in a paginated response.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
conformance_pack_rule_evaluation_results

Returns a list of ConformancePackEvaluationResult objects.

STRUCT(
"compliance_type" VARCHAR,
"evaluation_result_identifier" STRUCT(
"evaluation_result_qualifier" STRUCT(
"config_rule_name" VARCHAR,
"resource_type" VARCHAR,
"resource_id" VARCHAR,
"evaluation_mode" VARCHAR
),
"ordering_timestamp" TIMESTAMP_S,
"resource_evaluation_id" VARCHAR
),
"config_rule_invoked_time" TIMESTAMP_S,
"result_recorded_time" TIMESTAMP_S,
"annotation" VARCHAR
)[]
Show child fields
conformance_pack_rule_evaluation_results[]
Show child fields
conformance_pack_rule_evaluation_results[].annotation

Supplementary information about how the evaluation determined the compliance.

conformance_pack_rule_evaluation_results[].compliance_type

The compliance type. The allowed values are COMPLIANT and NON_COMPLIANT. INSUFFICIENT_DATA is not supported.

conformance_pack_rule_evaluation_results[].config_rule_invoked_time

The time when Config rule evaluated Amazon Web Services resource.

conformance_pack_rule_evaluation_results[].evaluation_result_identifier

Uniquely identifies an evaluation result.

Show child fields
conformance_pack_rule_evaluation_results[].evaluation_result_identifier.evaluation_result_qualifier

Identifies an Config rule used to evaluate an Amazon Web Services resource, and provides the type and ID of the evaluated resource.

Show child fields
conformance_pack_rule_evaluation_results[].evaluation_result_identifier.evaluation_result_qualifier.config_rule_name

The name of the Config rule that was used in the evaluation.

conformance_pack_rule_evaluation_results[].evaluation_result_identifier.evaluation_result_qualifier.evaluation_mode

The mode of an evaluation. The valid values are Detective or Proactive.

conformance_pack_rule_evaluation_results[].evaluation_result_identifier.evaluation_result_qualifier.resource_id

The ID of the evaluated Amazon Web Services resource.

conformance_pack_rule_evaluation_results[].evaluation_result_identifier.evaluation_result_qualifier.resource_type

The type of Amazon Web Services resource that was evaluated.

conformance_pack_rule_evaluation_results[].evaluation_result_identifier.ordering_timestamp

The time of the event that triggered the evaluation of your Amazon Web Services resources. The time can indicate when Config delivered a configuration item change notification, or it can indicate when Config delivered the configuration snapshot, depending on which event triggered the evaluation.

conformance_pack_rule_evaluation_results[].evaluation_result_identifier.resource_evaluation_id

A Unique ID for an evaluation result.

conformance_pack_rule_evaluation_results[].result_recorded_time

The time when Config recorded the evaluation result.