Skip to main content

detectors

Creates, updates, deletes or gets a detector resource or lists detectors in a region

Overview

Namedetectors
TypeResource
DescriptionResource Type definition for AWS::GuardDuty::Detector
Idawscc.guardduty.detectors

Fields

NameDatatypeDescription
finding_publishing_frequencystring
enableboolean
data_sourcesobject
featuresarray
idstring
tagsarray
regionstringAWS region.

For more information, see AWS::GuardDuty::Detector.

Methods

NameResourceAccessible byRequired Params
create_resourcedetectorsINSERTEnable, region
delete_resourcedetectorsDELETEIdentifier, region
update_resourcedetectorsUPDATEIdentifier, PatchDocument, region
list_resourcesdetectors_list_onlySELECTregion
get_resourcedetectorsSELECTIdentifier, region

SELECT examples

Gets all properties from an individual detector.

SELECT
region,
finding_publishing_frequency,
enable,
data_sources,
features,
id,
tags
FROM awscc.guardduty.detectors
WHERE
region = 'us-east-1' AND
Identifier = '{{ id }}';

INSERT example

Use the following StackQL query and manifest file to create a new detector resource, using stack-deploy.

/*+ create */
INSERT INTO awscc.guardduty.detectors (
Enable,
region
)
SELECT
'{{ enable }}',
'{{ region }}';

UPDATE example

Use the following StackQL query and manifest file to update a detector resource, using stack-deploy.

/*+ update */
UPDATE awscc.guardduty.detectors
SET PatchDocument = string('{{ {
"FindingPublishingFrequency": finding_publishing_frequency,
"Enable": enable,
"DataSources": data_sources,
"Features": features,
"Tags": tags
} | generate_patch_document }}')
WHERE
region = '{{ region }}' AND
Identifier = '{{ id }}';

DELETE example

/*+ delete */
DELETE FROM awscc.guardduty.detectors
WHERE
Identifier = '{{ id }}' AND
region = 'us-east-1';

Permissions

To operate on the detectors resource, the following permissions are required:

guardduty:CreateDetector,
guardduty:GetDetector,
guardduty:TagResource,
iam:CreateServiceLinkedRole,
iam:GetRole