Skip to content

aws.frauddetector.get_rules

Example SQL Queries

SELECT * FROM
aws.frauddetector.get_rules
WHERE
"detector_id" = 'VALUE';

Description

Get all rules for a detector (paginated) if ruleId and ruleVersion are not specified. Gets all rules for the detector and the ruleId if present (paginated). Gets a specific rule if both the ruleId and the ruleVersion are specified.

This is a paginated API. Providing null maxResults results in retrieving maximum of 100 records per page. If you provide maxResults the value must be between 50 and 100. To get the next page result, a provide a pagination token from GetRulesResult as part of your request. Null pagination token fetches the records from the beginning.

Table Definition

Column NameColumn Data Type
detector_id Required Input Column

The detector ID.

VARCHAR
max_results Input Column

The maximum number of rules to return for the request.

BIGINT
next_token Input Column

The next page token to be used in subsequent requests.

VARCHAR
rule_id Input Column

The rule ID.

VARCHAR
rule_version Input Column

The rule version.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
rule_details

The details of the requested rule.

STRUCT(
"rule_id" VARCHAR,
"description" VARCHAR,
"detector_id" VARCHAR,
"rule_version" VARCHAR,
"expression" VARCHAR,
"language" VARCHAR,
"outcomes" VARCHAR[],
"last_updated_time" VARCHAR,
"created_time" VARCHAR,
"arn" VARCHAR
)[]
Show child fields
rule_details[]
Show child fields
rule_details[].arn

The rule ARN.

rule_details[].created_time

The timestamp of when the rule was created.

rule_details[].description

The rule description.

rule_details[].detector_id

The detector for which the rule is associated.

rule_details[].expression

The rule expression.

rule_details[].language

The rule language.

rule_details[].last_updated_time

Timestamp of the last time the rule was updated.

rule_details[].outcomes[]
rule_details[].rule_id

The rule ID.

rule_details[].rule_version

The rule version.