| Column Name | Column Data Type |
malware_protection_plan_id Required Input Column
A unique identifier associated with Malware Protection plan resource. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
actions
Information about whether the tags will be added to the S3 object after scanning. | STRUCT( "tagging" STRUCT( "status" VARCHAR ) ) |
Show child fields- actions.tagging
Indicates whether the scanned S3 object will have tags about the scan result. Show child fields- actions.tagging.status
Indicates whether or not the tags will added.
|
arn
Amazon Resource Name (ARN) of the protected resource. | VARCHAR |
created_at
The timestamp when the Malware Protection plan resource was created. | TIMESTAMP_S |
protected_resource
Information about the protected resource that is associated with the created Malware Protection plan. Presently, S3Bucket is the only supported protected resource. | STRUCT( "s3_bucket" STRUCT( "bucket_name" VARCHAR, "object_prefixes" VARCHAR[] ) ) |
Show child fields- protected_resource.s3_bucket
Information about the protected S3 bucket resource. Show child fields- protected_resource.s3_bucket.bucket_name
Name of the S3 bucket.
- protected_resource.s3_bucket.object_prefixes[]
|
role
IAM role that includes the permissions required to scan and add tags to the associated protected resource. | VARCHAR |
status
Malware Protection plan status. | VARCHAR |
status_reasons
Information about the issue code and message associated to the status of your Malware Protection plan. | STRUCT( "code" VARCHAR, "message" VARCHAR )[] |
Show child fields- status_reasons[]
Show child fields- status_reasons[].code
Issue code.
- status_reasons[].message
Issue message that specifies the reason. For information about potential troubleshooting steps, see Troubleshooting Malware Protection for S3 status issues in the GuardDuty User Guide.
|
tags
Tags added to the Malware Protection plan resource. | MAP(VARCHAR, VARCHAR) |