Skip to content

aws.guardduty.get_usage_statistics

Example SQL Queries

SELECT * FROM
aws.guardduty.get_usage_statistics
WHERE
"detector_id" = 'VALUE'
AND "usage_statistic_type" = 'VALUE'
AND "usage_criteria" = 'VALUE';

Description

Lists Amazon GuardDuty usage statistics over the last 30 days for the specified detector ID. For newly enabled detectors or data sources, the cost returned will include only the usage so far under 30 days. This may differ from the cost metrics in the console, which project usage over 30 days to provide a monthly cost estimate. For more information, see Understanding How Usage Costs are Calculated.

Table Definition

Column NameColumn Data Type
detector_id Required Input Column

The ID of the detector that specifies the GuardDuty service whose usage statistics you want to retrieve.

VARCHAR
usage_criteria Required Input Column

Represents the criteria used for querying usage.

STRUCT(
"account_ids" VARCHAR[],
"data_sources" VARCHAR[],
"resources" VARCHAR[],
"features" VARCHAR[]
)
Show child fields
usage_criteria.account_ids[]
usage_criteria.data_sources[]
usage_criteria.features[]
usage_criteria.resources[]
usage_statistic_type Required Input Column

The type of usage statistics to retrieve.

VARCHAR
max_results Input Column

The maximum number of results to return in the response.

BIGINT
next_token Input Column

The pagination parameter to be used on the next list operation to retrieve more items.

VARCHAR
unit Input Column

The currency unit you would like to view your usage statistics in. Current valid values are USD.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
usage_statistics

The usage statistics object. If a UsageStatisticType was provided, the objects representing other types will be null.

STRUCT(
"sum_by_account" STRUCT(
"account_id" VARCHAR,
"total" STRUCT(
"amount" VARCHAR,
"unit" VARCHAR
)
)[],
"top_accounts_by_feature" STRUCT(
"feature" VARCHAR,
"accounts" STRUCT(
"account_id" VARCHAR,
"total" STRUCT(
"amount" VARCHAR,
"unit" VARCHAR
)
)[]
)[],
"sum_by_data_source" STRUCT(
"data_source" VARCHAR,
"total" STRUCT(
"amount" VARCHAR,
"unit" VARCHAR
)
)[],
"sum_by_resource" STRUCT(
"resource" VARCHAR,
"total" STRUCT(
"amount" VARCHAR,
"unit" VARCHAR
)
)[],
"top_resources" STRUCT(
"resource" VARCHAR,
"total" STRUCT(
"amount" VARCHAR,
"unit" VARCHAR
)
)[],
"sum_by_feature" STRUCT(
"feature" VARCHAR,
"total" STRUCT(
"amount" VARCHAR,
"unit" VARCHAR
)
)[]
)
Show child fields
usage_statistics.sum_by_account[]
Show child fields
usage_statistics.sum_by_account[].account_id

The Account ID that generated usage.

usage_statistics.sum_by_account[].total

Represents the total of usage for the Account ID.

Show child fields
usage_statistics.sum_by_account[].total.amount

The total usage.

usage_statistics.sum_by_account[].total.unit

The currency unit that the amount is given in.

usage_statistics.sum_by_data_source[]
Show child fields
usage_statistics.sum_by_data_source[].data_source

The data source type that generated usage.

usage_statistics.sum_by_data_source[].total

Represents the total of usage for the specified data source.

Show child fields
usage_statistics.sum_by_data_source[].total.amount

The total usage.

usage_statistics.sum_by_data_source[].total.unit

The currency unit that the amount is given in.

usage_statistics.sum_by_feature[]
Show child fields
usage_statistics.sum_by_feature[].feature

The feature that generated the usage cost.

usage_statistics.sum_by_feature[].total

Contains the total usage with the corresponding currency unit for that value.

Show child fields
usage_statistics.sum_by_feature[].total.amount

The total usage.

usage_statistics.sum_by_feature[].total.unit

The currency unit that the amount is given in.

usage_statistics.sum_by_resource[]
Show child fields
usage_statistics.sum_by_resource[].resource

The Amazon Web Services resource that generated usage.

usage_statistics.sum_by_resource[].total

Represents the sum total of usage for the specified resource type.

Show child fields
usage_statistics.sum_by_resource[].total.amount

The total usage.

usage_statistics.sum_by_resource[].total.unit

The currency unit that the amount is given in.

usage_statistics.top_accounts_by_feature[]
Show child fields
usage_statistics.top_accounts_by_feature[].accounts[]
Show child fields
usage_statistics.top_accounts_by_feature[].accounts[].account_id

The unique account ID.

usage_statistics.top_accounts_by_feature[].accounts[].total

Contains the total usage with the corresponding currency unit for that value.

Show child fields
usage_statistics.top_accounts_by_feature[].accounts[].total.amount

The total usage.

usage_statistics.top_accounts_by_feature[].accounts[].total.unit

The currency unit that the amount is given in.

usage_statistics.top_accounts_by_feature[].feature

Features by which you can generate the usage statistics.

RDS_LOGIN_EVENTS is currently not supported with topAccountsByFeature.

usage_statistics.top_resources[]
Show child fields
usage_statistics.top_resources[].resource

The Amazon Web Services resource that generated usage.

usage_statistics.top_resources[].total

Represents the sum total of usage for the specified resource type.

Show child fields
usage_statistics.top_resources[].total.amount

The total usage.

usage_statistics.top_resources[].total.unit

The currency unit that the amount is given in.