Skip to content

aws.ssm.list_compliance_summaries

Example SQL Queries

SELECT * FROM
aws.ssm.list_compliance_summaries;

Description

Returns a summary count of compliant and non-compliant resources for a compliance type. For example, this call can return State Manager associations, patches, or custom compliance types according to the filter criteria that you specify.

Table Definition

Column NameColumn Data Type
filters Input Column

One or more compliance or inventory filters. Use a filter to return a more specific list of results.

STRUCT(
"key" VARCHAR,
"values" VARCHAR[],
"type" VARCHAR
)[]
Show child fields
filters[]
Show child fields
filters[].key

The name of the filter.

filters[].type

The type of comparison that should be performed for the value: Equal, NotEqual, BeginWith, LessThan, or GreaterThan.

filters[].values[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
compliance_type

The type of compliance item. For example, the compliance type can be Association, Patch, or Custom:string.

VARCHAR
compliant_summary

A list of COMPLIANT items for the specified compliance type.

STRUCT(
"compliant_count" BIGINT,
"severity_summary" STRUCT(
"critical_count" BIGINT,
"high_count" BIGINT,
"medium_count" BIGINT,
"low_count" BIGINT,
"informational_count" BIGINT,
"unspecified_count" BIGINT
)
)
Show child fields
compliant_summary.compliant_count

The total number of resources that are compliant.

compliant_summary.severity_summary

A summary of the compliance severity by compliance type.

Show child fields
compliant_summary.severity_summary.critical_count

The total number of resources or compliance items that have a severity level of Critical. Critical severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.high_count

The total number of resources or compliance items that have a severity level of high. High severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.informational_count

The total number of resources or compliance items that have a severity level of informational. Informational severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.low_count

The total number of resources or compliance items that have a severity level of low. Low severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.medium_count

The total number of resources or compliance items that have a severity level of medium. Medium severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.unspecified_count

The total number of resources or compliance items that have a severity level of unspecified. Unspecified severity is determined by the organization that published the compliance items.

non_compliant_summary

A list of NON_COMPLIANT items for the specified compliance type.

STRUCT(
"non_compliant_count" BIGINT,
"severity_summary" STRUCT(
"critical_count" BIGINT,
"high_count" BIGINT,
"medium_count" BIGINT,
"low_count" BIGINT,
"informational_count" BIGINT,
"unspecified_count" BIGINT
)
)
Show child fields
non_compliant_summary.non_compliant_count

The total number of compliance items that aren't compliant.

non_compliant_summary.severity_summary

A summary of the non-compliance severity by compliance type

Show child fields
non_compliant_summary.severity_summary.critical_count

The total number of resources or compliance items that have a severity level of Critical. Critical severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.high_count

The total number of resources or compliance items that have a severity level of high. High severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.informational_count

The total number of resources or compliance items that have a severity level of informational. Informational severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.low_count

The total number of resources or compliance items that have a severity level of low. Low severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.medium_count

The total number of resources or compliance items that have a severity level of medium. Medium severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.unspecified_count

The total number of resources or compliance items that have a severity level of unspecified. Unspecified severity is determined by the organization that published the compliance items.