| Column Name | Column Data Type |
filters Input Column
Filters the list of incident records you want to search through. You can filter on the following keys: -
creationTime -
impact -
status -
createdBy Note the following when when you use Filters: -
If you don't specify a Filter, the response includes all incident records. -
If you specify more than one filter in a single request, the response returns incident records that match all filters. -
If you specify a filter with more than one value, the response returns incident records that match any of the values provided. | STRUCT( "condition" STRUCT( "after" TIMESTAMP_S, "before" TIMESTAMP_S, "equals" STRUCT( "integer_values" BIGINT[], "string_values" VARCHAR[] ) ), "key" VARCHAR )[] |
Show child fields- filters[]
Show child fields- filters[].condition
The condition accepts before or after a specified time, equal to a string, or equal to an integer. Show child fields- filters[].condition.after
After the specified timestamp.
- filters[].condition.before
Before the specified timestamp
- filters[].condition.equals
The value is equal to the provided string or integer. Show child fields- filters[].condition.equals.integer_values[]
- filters[].condition.equals.string_values[]
- filters[].key
The key that you're filtering on.
|
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
arn
The Amazon Resource Name (ARN) of the incident. | VARCHAR |
creation_time
The timestamp for when the incident was created. | TIMESTAMP_S |
impact
Defines the impact to customers and applications. | BIGINT |
incident_record_source
What caused Incident Manager to create the incident. | STRUCT( "created_by" VARCHAR, "invoked_by" VARCHAR, "resource_arn" VARCHAR, "source" VARCHAR ) |
Show child fields- incident_record_source.created_by
The principal that started the incident.
- incident_record_source.invoked_by
The service principal that assumed the role specified in createdBy. If no service principal assumed the role this will be left blank.
- incident_record_source.resource_arn
The resource that caused the incident to be created.
- incident_record_source.source
The service that started the incident. This can be manually created from Incident Manager, automatically created using an Amazon CloudWatch alarm, or Amazon EventBridge event.
|
resolved_time
The timestamp for when the incident was resolved. | TIMESTAMP_S |
status
The current status of the incident. | VARCHAR |
title
The title of the incident. This value is either provided by the response plan or overwritten on creation. | VARCHAR |