| Column Name | Column Data Type |
command_id Input Column
The command against which this invocation was requested. | VARCHAR |
details Input Column
(Optional) If set this returns the response of the command executions and any command output. The default value is false. | BOOLEAN |
filters Input Column
(Optional) One or more filters. Use a filter to return a more specific list of results. | STRUCT( "key" VARCHAR, "value" VARCHAR )[] |
Show child fields- filters[]
Show child fields- filters[].key
The name of the filter. The ExecutionStage filter can't be used with the ListCommandInvocations operation, only with ListCommands.
- filters[].value
The filter value. Valid values for each filter key are as follows: -
InvokedAfter: Specify a timestamp to limit your results. For example, specify 2021-07-07T00:00:00Z to see a list of command executions occurring July 7, 2021, and later. -
InvokedBefore: Specify a timestamp to limit your results. For example, specify 2021-07-07T00:00:00Z to see a list of command executions from before July 7, 2021. -
Status: Specify a valid command status to see a list of all command executions with that status. The status choices depend on the API you call. The status values you can specify for ListCommands are: The status values you can specify for ListCommandInvocations are: -
DocumentName: Specify name of the Amazon Web Services Systems Manager document (SSM document) for which you want to see command execution results. For example, specify AWS-RunPatchBaseline to see command executions that used this SSM document to perform security patching operations on managed nodes. -
ExecutionStage: Specify one of the following values (ListCommands operations only):
|
instance_id Input Column
The managed node ID in which this invocation was requested. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
cloud_watch_output_config
Amazon CloudWatch Logs information where you want Amazon Web Services Systems Manager to send the command output. | STRUCT( "cloud_watch_log_group_name" VARCHAR, "cloud_watch_output_enabled" BOOLEAN ) |
Show child fields- cloud_watch_output_config.cloud_watch_log_group_name
The name of the CloudWatch Logs log group where you want to send command output. If you don't specify a group name, Amazon Web Services Systems Manager automatically creates a log group for you. The log group uses the following naming format: aws/ssm/SystemsManagerDocumentName
- cloud_watch_output_config.cloud_watch_output_enabled
Enables Systems Manager to send command output to CloudWatch Logs.
|
command_plugins
Plugins processed by the command. | STRUCT( "name" VARCHAR, "status" VARCHAR, "status_details" VARCHAR, "response_code" BIGINT, "response_start_date_time" TIMESTAMP_S, "response_finish_date_time" TIMESTAMP_S, "output" VARCHAR, "standard_output_url" VARCHAR, "standard_error_url" VARCHAR, "output_s3_region" VARCHAR, "output_s3_bucket_name" VARCHAR, "output_s3_key_prefix" VARCHAR )[] |
Show child fields- command_plugins[]
Show child fields- command_plugins[].name
The name of the plugin. Must be one of the following: aws:updateAgent, aws:domainjoin, aws:applications, aws:runPowerShellScript, aws:psmodule, aws:cloudWatch, aws:runShellScript, or aws:updateSSMAgent.
- command_plugins[].output
Output of the plugin execution.
- command_plugins[].output_s3_bucket_name
The S3 bucket where the responses to the command executions should be stored. This was requested when issuing the command. For example, in the following response: doc-example-bucket/ab19cb99-a030-46dd-9dfc-8eSAMPLEPre-Fix/i-02573cafcfEXAMPLE/awsrunShellScript doc-example-bucket is the name of the S3 bucket; ab19cb99-a030-46dd-9dfc-8eSAMPLEPre-Fix is the name of the S3 prefix; i-02573cafcfEXAMPLE is the managed node ID; awsrunShellScript is the name of the plugin.
- command_plugins[].output_s3_key_prefix
The S3 directory path inside the bucket where the responses to the command executions should be stored. This was requested when issuing the command. For example, in the following response: doc-example-bucket/ab19cb99-a030-46dd-9dfc-8eSAMPLEPre-Fix/i-02573cafcfEXAMPLE/awsrunShellScript doc-example-bucket is the name of the S3 bucket; ab19cb99-a030-46dd-9dfc-8eSAMPLEPre-Fix is the name of the S3 prefix; i-02573cafcfEXAMPLE is the managed node ID; awsrunShellScript is the name of the plugin.
- command_plugins[].output_s3_region
(Deprecated) You can no longer specify this parameter. The system ignores it. Instead, Amazon Web Services Systems Manager automatically determines the S3 bucket region.
- command_plugins[].response_code
A numeric response code generated after running the plugin.
- command_plugins[].response_finish_date_time
The time the plugin stopped running. Could stop prematurely if, for example, a cancel command was sent.
- command_plugins[].response_start_date_time
The time the plugin started running.
- command_plugins[].standard_error_url
The URL for the complete text written by the plugin to stderr. If execution isn't yet complete, then this string is empty.
- command_plugins[].standard_output_url
The URL for the complete text written by the plugin to stdout in Amazon S3. If the S3 bucket for the command wasn't specified, then this string is empty.
- command_plugins[].status
The status of this plugin. You can run a document with multiple plugins.
- command_plugins[].status_details
A detailed status of the plugin execution. StatusDetails includes more information than Status because it includes states resulting from error and concurrency control parameters. StatusDetails can show different results than Status. For more information about these statuses, see Understanding command statuses in the Amazon Web Services Systems Manager User Guide. StatusDetails can be one of the following values: -
Pending: The command hasn't been sent to the managed node. -
In Progress: The command has been sent to the managed node but hasn't reached a terminal state. -
Success: The execution of the command or plugin was successfully completed. This is a terminal state. -
Delivery Timed Out: The command wasn't delivered to the managed node before the delivery timeout expired. Delivery timeouts don't count against the parent command's MaxErrors limit, but they do contribute to whether the parent command status is Success or Incomplete. This is a terminal state. -
Execution Timed Out: Command execution started on the managed node, but the execution wasn't complete before the execution timeout expired. Execution timeouts count against the MaxErrors limit of the parent command. This is a terminal state. -
Failed: The command wasn't successful on the managed node. For a plugin, this indicates that the result code wasn't zero. For a command invocation, this indicates that the result code for one or more plugins wasn't zero. Invocation failures count against the MaxErrors limit of the parent command. This is a terminal state. -
Cancelled: The command was terminated before it was completed. This is a terminal state. -
Undeliverable: The command can't be delivered to the managed node. The managed node might not exist, or it might not be responding. Undeliverable invocations don't count against the parent command's MaxErrors limit, and they don't contribute to whether the parent command status is Success or Incomplete. This is a terminal state. -
Terminated: The parent command exceeded its MaxErrors limit and subsequent command invocations were canceled by the system. This is a terminal state.
|
comment
User-specified information about the command, such as a brief description of what the command should do. | VARCHAR |
document_name
The document name that was requested for execution. | VARCHAR |
document_version
The Systems Manager document (SSM document) version. | VARCHAR |
instance_name
The fully qualified host name of the managed node. | VARCHAR |
notification_config
Configurations for sending notifications about command status changes on a per managed node basis. | STRUCT( "notification_arn" VARCHAR, "notification_events" VARCHAR[], "notification_type" VARCHAR ) |
Show child fields- notification_config.notification_arn
An Amazon Resource Name (ARN) for an Amazon Simple Notification Service (Amazon SNS) topic. Run Command pushes notifications about command status changes to this topic.
- notification_config.notification_events[]
- notification_config.notification_type
The type of notification. -
Command: Receive notification when the status of a command changes. -
Invocation: For commands sent to multiple managed nodes, receive notification on a per-node basis when the status of a command changes.
|
requested_date_time
The time and date the request was sent to this managed node. | TIMESTAMP_S |
service_role
The Identity and Access Management (IAM) service role that Run Command, a capability of Amazon Web Services Systems Manager, uses to act on your behalf when sending notifications about command status changes on a per managed node basis. | VARCHAR |
standard_error_url
The URL to the plugin's StdErr file in Amazon Simple Storage Service (Amazon S3), if the S3 bucket was defined for the parent command. For an invocation, StandardErrorUrl is populated if there is just one plugin defined for the command, and the S3 bucket was defined for the command. | VARCHAR |
standard_output_url
The URL to the plugin's StdOut file in Amazon Simple Storage Service (Amazon S3), if the S3 bucket was defined for the parent command. For an invocation, StandardOutputUrl is populated if there is just one plugin defined for the command, and the S3 bucket was defined for the command. | VARCHAR |
status
Whether or not the invocation succeeded, failed, or is pending. | VARCHAR |
status_details
A detailed status of the command execution for each invocation (each managed node targeted by the command). StatusDetails includes more information than Status because it includes states resulting from error and concurrency control parameters. StatusDetails can show different results than Status. For more information about these statuses, see Understanding command statuses in the Amazon Web Services Systems Manager User Guide. StatusDetails can be one of the following values: -
Pending: The command hasn't been sent to the managed node. -
In Progress: The command has been sent to the managed node but hasn't reached a terminal state. -
Success: The execution of the command or plugin was successfully completed. This is a terminal state. -
Delivery Timed Out: The command wasn't delivered to the managed node before the delivery timeout expired. Delivery timeouts don't count against the parent command's MaxErrors limit, but they do contribute to whether the parent command status is Success or Incomplete. This is a terminal state. -
Execution Timed Out: Command execution started on the managed node, but the execution wasn't complete before the execution timeout expired. Execution timeouts count against the MaxErrors limit of the parent command. This is a terminal state. -
Failed: The command wasn't successful on the managed node. For a plugin, this indicates that the result code wasn't zero. For a command invocation, this indicates that the result code for one or more plugins wasn't zero. Invocation failures count against the MaxErrors limit of the parent command. This is a terminal state. -
Cancelled: The command was terminated before it was completed. This is a terminal state. -
Undeliverable: The command can't be delivered to the managed node. The managed node might not exist or might not be responding. Undeliverable invocations don't count against the parent command's MaxErrors limit and don't contribute to whether the parent command status is Success or Incomplete. This is a terminal state. -
Terminated: The parent command exceeded its MaxErrors limit and subsequent command invocations were canceled by the system. This is a terminal state. -
Delayed: The system attempted to send the command to the managed node but wasn't successful. The system retries again. | VARCHAR |
trace_output
Gets the trace output sent by the agent. | VARCHAR |