Skip to content

aws.inspector.list_findings

Example SQL Queries

SELECT * FROM
aws.inspector.list_findings;

Description

Lists findings that are generated by the assessment runs that are specified by the ARNs of the assessment runs.

Table Definition

Column NameColumn Data Type
assessment_run_arns Input Column

The ARNs of the assessment runs that generate the findings that you want to list.

VARCHAR[]
Show child fields
assessment_run_arns[]
filter Input Column

You can use this parameter to specify a subset of data to be included in the action's response.

For a record to match a filter, all specified filter attributes must match. When multiple values are specified for a filter attribute, any of the values can match.

STRUCT(
"agent_ids" VARCHAR[],
"auto_scaling_groups" VARCHAR[],
"rule_names" VARCHAR[],
"severities" VARCHAR[],
"rules_package_arns" VARCHAR[],
"attributes" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"user_attributes" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"creation_time_range" STRUCT(
"begin_date" TIMESTAMP_S,
"end_date" TIMESTAMP_S
)
)
Show child fields
filter.agent_ids[]
filter.attributes[]
Show child fields
filter.attributes[].key

The attribute key.

filter.attributes[].value

The value assigned to the attribute key.

filter.auto_scaling_groups[]
filter.creation_time_range

The time range during which the finding is generated.

Show child fields
filter.creation_time_range.begin_date

The minimum value of the timestamp range.

filter.creation_time_range.end_date

The maximum value of the timestamp range.

filter.rule_names[]
filter.rules_package_arns[]
filter.severities[]
filter.user_attributes[]
Show child fields
filter.user_attributes[].key

The attribute key.

filter.user_attributes[].value

The value assigned to the attribute key.

_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
finding_arns
VARCHAR