Skip to content

aws.guardduty.get_coverage_statistics

Example SQL Queries

SELECT * FROM
aws.guardduty.get_coverage_statistics
WHERE
"detector_id" = 'VALUE'
AND "statistics_type" = 'VALUE';

Description

Retrieves aggregated statistics for your account. If you are a GuardDuty administrator, you can retrieve the statistics for all the resources associated with the active member accounts in your organization who have enabled Runtime Monitoring and have the GuardDuty security agent running on their resources.

Table Definition

Column NameColumn Data Type
detector_id Required Input Column

The unique ID of the GuardDuty detector associated to the coverage statistics.

VARCHAR
statistics_type Required Input Column

Represents the statistics type used to aggregate the coverage details.

VARCHAR[]
Show child fields
statistics_type[]
filter_criteria Input Column

Represents the criteria used to filter the coverage statistics

STRUCT(
"filter_criterion" STRUCT(
"criterion_key" VARCHAR,
"filter_condition" STRUCT(
"equals" VARCHAR[],
"not_equals" VARCHAR[]
)
)[]
)
Show child fields
filter_criteria.filter_criterion[]
Show child fields
filter_criteria.filter_criterion[].criterion_key

An enum value representing possible filter fields.

Replace the enum value CLUSTER_NAME with EKS_CLUSTER_NAME. CLUSTER_NAME has been deprecated.

filter_criteria.filter_criterion[].filter_condition

Contains information about the condition.

Show child fields
filter_criteria.filter_criterion[].filter_condition.equals[]
filter_criteria.filter_criterion[].filter_condition.not_equals[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
coverage_statistics

Represents the count aggregated by the statusCode and resourceType.

STRUCT(
"count_by_resource_type" MAP(VARCHAR, BIGINT),
"count_by_coverage_status" MAP(VARCHAR, BIGINT)
)
Show child fields
coverage_statistics.count_by_coverage_status

Represents coverage statistics for EKS clusters aggregated by coverage status.

coverage_statistics.count_by_resource_type

Represents coverage statistics for EKS clusters aggregated by resource type.