Skip to content

aws.ssm_incidents.list_incident_records

Example SQL Queries

SELECT * FROM
aws.ssm_incidents.list_incident_records;

Description

Lists all incident records in your account. Use this command to retrieve the Amazon Resource Name (ARN) of the incident record you want to update.

Table Definition

Column NameColumn Data Type
filters Input Column

Filters the list of incident records you want to search through. You can filter on the following keys:

  • creationTime

  • impact

  • status

  • createdBy

Note the following when when you use Filters:

  • If you don't specify a Filter, the response includes all incident records.

  • If you specify more than one filter in a single request, the response returns incident records that match all filters.

  • If you specify a filter with more than one value, the response returns incident records that match any of the values provided.

STRUCT(
"condition" STRUCT(
"after" TIMESTAMP_S,
"before" TIMESTAMP_S,
"equals" STRUCT(
"integer_values" BIGINT[],
"string_values" VARCHAR[]
)
),
"key" VARCHAR
)[]
Show child fields
filters[]
Show child fields
filters[].condition

The condition accepts before or after a specified time, equal to a string, or equal to an integer.

Show child fields
filters[].condition.after

After the specified timestamp.

filters[].condition.before

Before the specified timestamp

filters[].condition.equals

The value is equal to the provided string or integer.

Show child fields
filters[].condition.equals.integer_values[]
filters[].condition.equals.string_values[]
filters[].key

The key that you're filtering on.

_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
arn

The Amazon Resource Name (ARN) of the incident.

VARCHAR
creation_time

The timestamp for when the incident was created.

TIMESTAMP_S
impact

Defines the impact to customers and applications.

BIGINT
incident_record_source

What caused Incident Manager to create the incident.

STRUCT(
"created_by" VARCHAR,
"invoked_by" VARCHAR,
"resource_arn" VARCHAR,
"source" VARCHAR
)
Show child fields
incident_record_source.created_by

The principal that started the incident.

incident_record_source.invoked_by

The service principal that assumed the role specified in createdBy. If no service principal assumed the role this will be left blank.

incident_record_source.resource_arn

The resource that caused the incident to be created.

incident_record_source.source

The service that started the incident. This can be manually created from Incident Manager, automatically created using an Amazon CloudWatch alarm, or Amazon EventBridge event.

resolved_time

The timestamp for when the incident was resolved.

TIMESTAMP_S
status

The current status of the incident.

VARCHAR
title

The title of the incident. This value is either provided by the response plan or overwritten on creation.

VARCHAR