Skip to content

aws.ec2.get_flow_logs_integration_template

Example SQL Queries

SELECT * FROM
aws.ec2.get_flow_logs_integration_template
WHERE
"flow_log_id" = 'VALUE'
AND "config_delivery_s3_destination_arn" = 'VALUE'
AND "integrate_services" = 'VALUE';

Description

Generates a CloudFormation template that streamlines and automates the integration of VPC flow logs with Amazon Athena. This make it easier for you to query and gain insights from VPC flow logs data. Based on the information that you provide, we configure resources in the template to do the following:

  • Create a table in Athena that maps fields to a custom log format

  • Create a Lambda function that updates the table with new partitions on a daily, weekly, or monthly basis

  • Create a table partitioned between two timestamps in the past

  • Create a set of named queries in Athena that you can use to get started quickly

GetFlowLogsIntegrationTemplate does not support integration between Amazon Web Services Transit Gateway Flow Logs and Amazon Athena.

Table Definition

Column NameColumn Data Type
config_delivery_s3_destination_arn Required Input Column

To store the CloudFormation template in Amazon S3, specify the location in Amazon S3.

VARCHAR
flow_log_id Required Input Column

The ID of the flow log.

VARCHAR
integrate_services Required Input Column

Information about the service integration.

STRUCT(
"athena_integrations" STRUCT(
"integration_result_s3_destination_arn" VARCHAR,
"partition_load_frequency" VARCHAR,
"partition_start_date" TIMESTAMP_S,
"partition_end_date" TIMESTAMP_S
)[]
)
Show child fields
integrate_services.athena_integrations[]
Show child fields
integrate_services.athena_integrations[].integration_result_s3_destination_arn

The location in Amazon S3 to store the generated CloudFormation template.

integrate_services.athena_integrations[].partition_end_date

The end date for the partition.

integrate_services.athena_integrations[].partition_load_frequency

The schedule for adding new partitions to the table.

integrate_services.athena_integrations[].partition_start_date

The start date for the partition.

dry_run Input Column

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

BOOLEAN
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
result

The generated CloudFormation template.

VARCHAR