Skip to content

aws.shield.describe_attack_statistics

Example SQL Queries

SELECT * FROM
aws.shield.describe_attack_statistics;

Description

Provides information about the number and type of attacks Shield has detected in the last year for all resources that belong to your account, regardless of whether you've defined Shield protections for them. This operation is available to Shield customers as well as to Shield Advanced customers.

The operation returns data for the time range of midnight UTC, one year ago, to midnight UTC, today. For example, if the current time is 2020-10-26 15:39:32 PDT, equal to 2020-10-26 22:39:32 UTC, then the time range for the attack data returned is from 2019-10-26 00:00:00 UTC to 2020-10-26 00:00:00 UTC.

The time range indicates the period covered by the attack statistics data items.

Table Definition

Column NameColumn Data Type
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

data_items

The data that describes the attacks detected during the time period.

STRUCT(
"attack_volume" STRUCT(
"bits_per_second" STRUCT(
"max" DOUBLE
),
"packets_per_second" STRUCT(
"max" DOUBLE
),
"requests_per_second" STRUCT(
"max" DOUBLE
)
),
"attack_count" BIGINT
)[]
Show child fields
data_items[]
Show child fields
data_items[].attack_count

The number of attacks detected during the time period. This is always present, but might be zero.

data_items[].attack_volume

Information about the volume of attacks during the time period. If the accompanying AttackCount is zero, this setting might be empty.

Show child fields
data_items[].attack_volume.bits_per_second

A statistics object that uses bits per second as the unit. This is included for network level attacks.

Show child fields
data_items[].attack_volume.bits_per_second.max

The maximum attack volume observed for the given unit.

data_items[].attack_volume.packets_per_second

A statistics object that uses packets per second as the unit. This is included for network level attacks.

Show child fields
data_items[].attack_volume.packets_per_second.max

The maximum attack volume observed for the given unit.

data_items[].attack_volume.requests_per_second

A statistics object that uses requests per second as the unit. This is included for application level attacks, and is only available for accounts that are subscribed to Shield Advanced.

Show child fields
data_items[].attack_volume.requests_per_second.max

The maximum attack volume observed for the given unit.

time_range

The time range of the attack.

STRUCT(
"from_inclusive" TIMESTAMP_S,
"to_exclusive" TIMESTAMP_S
)
Show child fields
time_range.from_inclusive

The start time, in Unix time in seconds.

time_range.to_exclusive

The end time, in Unix time in seconds.