Skip to content

aws.macie2.get_findings_filter

Example SQL Queries

SELECT * FROM
aws.macie2.get_findings_filter
WHERE
"id" = 'VALUE';

Description

Retrieves the criteria and other settings for a findings filter.

Table Definition

Column NameColumn Data Type
id Required Input Column

The unique identifier for the filter.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
action

The action that's performed on findings that match the filter criteria (findingCriteria). Possible values are: ARCHIVE, suppress (automatically archive) the findings; and, NOOP, don't perform any action on the findings.

VARCHAR
arn

The Amazon Resource Name (ARN) of the filter.

VARCHAR
description

The custom description of the filter.

VARCHAR
finding_criteria

The criteria that's used to filter findings.

STRUCT(
"criterion" MAP(VARCHAR, STRUCT(
"eq" VARCHAR[],
"eq_exact_match" VARCHAR[],
"gt" BIGINT,
"gte" BIGINT,
"lt" BIGINT,
"lte" BIGINT,
"neq" VARCHAR[]
))
)
Show child fields
finding_criteria.criterion

A condition that specifies the property, operator, and one or more values to use to filter the results.

name

The custom name of the filter.

VARCHAR
position

The position of the filter in the list of saved filters on the Amazon Macie console. This value also determines the order in which the filter is applied to findings, relative to other filters that are also applied to the findings.

BIGINT
tags

A map of key-value pairs that specifies which tags (keys and values) are associated with the filter.

MAP(VARCHAR, VARCHAR)