| Column Name | Column Data Type |
detector_id Required Input Column
The unique ID of the detector that the filter is associated with. | VARCHAR |
filter_name Required Input Column
The name of the filter you want to get. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
action
Specifies the action that is to be applied to the findings that match the filter. | VARCHAR |
description
The description of the filter. | VARCHAR |
finding_criteria
Represents the criteria to be used in the filter for querying findings. | STRUCT( "criterion" MAP(VARCHAR, STRUCT( "eq" VARCHAR[], "neq" VARCHAR[], "gt" BIGINT, "gte" BIGINT, "lt" BIGINT, "lte" BIGINT, "equals" VARCHAR[], "not_equals" VARCHAR[], "greater_than" BIGINT, "greater_than_or_equal" BIGINT, "less_than" BIGINT, "less_than_or_equal" BIGINT )) ) |
Show child fields- finding_criteria.criterion
Represents a map of finding properties that match specified conditions and values when querying findings.
|
name
The name of the filter. | VARCHAR |
rank
Specifies the position of the filter in the list of current filters. Also specifies the order in which this filter is applied to the findings. | BIGINT |
tags
The tags of the filter resource. | MAP(VARCHAR, VARCHAR) |