Skip to content

aws.fms.list_compliance_status

Example SQL Queries

SELECT * FROM
aws.fms.list_compliance_status
WHERE
"policy_id" = 'VALUE';

Description

Returns an array of PolicyComplianceStatus objects. Use PolicyComplianceStatus to get a summary of which member accounts are protected by the specified policy.

Table Definition

Column NameColumn Data Type
policy_id Required Input Column

The ID of the Firewall Manager policy.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
evaluation_results

An array of EvaluationResult objects.

STRUCT(
"compliance_status" VARCHAR,
"violator_count" BIGINT,
"evaluation_limit_exceeded" BOOLEAN
)[]
Show child fields
evaluation_results[]
Show child fields
evaluation_results[].compliance_status

Describes an Amazon Web Services account's compliance with the Firewall Manager policy.

evaluation_results[].evaluation_limit_exceeded

Indicates that over 100 resources are noncompliant with the Firewall Manager policy.

evaluation_results[].violator_count

The number of resources that are noncompliant with the specified policy. For WAF and Shield Advanced policies, a resource is considered noncompliant if it is not associated with the policy. For security group policies, a resource is considered noncompliant if it doesn't comply with the rules of the policy and remediation is disabled or not possible.

issue_info_map

Details about problems with dependent services, such as WAF or Config, and the error message received that indicates the problem with the service.

MAP(VARCHAR, VARCHAR)
last_updated

Timestamp of the last update to the EvaluationResult objects.

TIMESTAMP_S
member_account

The member account ID.

VARCHAR
policy_name

The name of the Firewall Manager policy.

VARCHAR
policy_owner

The Amazon Web Services account that created the Firewall Manager policy.

VARCHAR