Skip to content

aws.ssm.list_resource_compliance_summaries

Example SQL Queries

SELECT * FROM
aws.ssm.list_resource_compliance_summaries;

Description

Returns a resource-level summary count. The summary includes information about compliant and non-compliant statuses and detailed compliance-item severity counts, according to the filter criteria you specify.

Table Definition

Column NameColumn Data Type
filters Input Column

One or more filters. Use a filter to return a more specific list of results.

STRUCT(
"key" VARCHAR,
"values" VARCHAR[],
"type" VARCHAR
)[]
Show child fields
filters[]
Show child fields
filters[].key

The name of the filter.

filters[].type

The type of comparison that should be performed for the value: Equal, NotEqual, BeginWith, LessThan, or GreaterThan.

filters[].values[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
compliance_type

The compliance type.

VARCHAR
compliant_summary

A list of items that are compliant for the resource.

STRUCT(
"compliant_count" BIGINT,
"severity_summary" STRUCT(
"critical_count" BIGINT,
"high_count" BIGINT,
"medium_count" BIGINT,
"low_count" BIGINT,
"informational_count" BIGINT,
"unspecified_count" BIGINT
)
)
Show child fields
compliant_summary.compliant_count

The total number of resources that are compliant.

compliant_summary.severity_summary

A summary of the compliance severity by compliance type.

Show child fields
compliant_summary.severity_summary.critical_count

The total number of resources or compliance items that have a severity level of Critical. Critical severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.high_count

The total number of resources or compliance items that have a severity level of high. High severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.informational_count

The total number of resources or compliance items that have a severity level of informational. Informational severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.low_count

The total number of resources or compliance items that have a severity level of low. Low severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.medium_count

The total number of resources or compliance items that have a severity level of medium. Medium severity is determined by the organization that published the compliance items.

compliant_summary.severity_summary.unspecified_count

The total number of resources or compliance items that have a severity level of unspecified. Unspecified severity is determined by the organization that published the compliance items.

execution_summary

Information about the execution.

STRUCT(
"execution_time" TIMESTAMP_S,
"execution_id" VARCHAR,
"execution_type" VARCHAR
)
Show child fields
execution_summary.execution_id

An ID created by the system when PutComplianceItems was called. For example, CommandID is a valid execution ID. You can use this ID in subsequent calls.

execution_summary.execution_time

The time the execution ran as a datetime object that is saved in the following format: yyyy-MM-dd'T'HH:mm:ss'Z'

execution_summary.execution_type

The type of execution. For example, Command is a valid execution type.

non_compliant_summary

A list of items that aren't compliant for the resource.

STRUCT(
"non_compliant_count" BIGINT,
"severity_summary" STRUCT(
"critical_count" BIGINT,
"high_count" BIGINT,
"medium_count" BIGINT,
"low_count" BIGINT,
"informational_count" BIGINT,
"unspecified_count" BIGINT
)
)
Show child fields
non_compliant_summary.non_compliant_count

The total number of compliance items that aren't compliant.

non_compliant_summary.severity_summary

A summary of the non-compliance severity by compliance type

Show child fields
non_compliant_summary.severity_summary.critical_count

The total number of resources or compliance items that have a severity level of Critical. Critical severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.high_count

The total number of resources or compliance items that have a severity level of high. High severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.informational_count

The total number of resources or compliance items that have a severity level of informational. Informational severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.low_count

The total number of resources or compliance items that have a severity level of low. Low severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.medium_count

The total number of resources or compliance items that have a severity level of medium. Medium severity is determined by the organization that published the compliance items.

non_compliant_summary.severity_summary.unspecified_count

The total number of resources or compliance items that have a severity level of unspecified. Unspecified severity is determined by the organization that published the compliance items.

overall_severity

The highest severity item found for the resource. The resource is compliant for this item.

VARCHAR
resource_id

The resource ID.

VARCHAR
resource_type

The resource type.

VARCHAR
status

The compliance status for the resource.

VARCHAR