Skip to main content

compliance_details_by_resources

Creates, updates, deletes, gets or lists a compliance_details_by_resources resource.

Overview

Namecompliance_details_by_resources
TypeResource
Idaws.config.compliance_details_by_resources

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
annotationstringSupplementary information about how the evaluation determined the compliance.
compliance_typestringIndicates whether the Amazon Web Services resource complies with the Config rule that evaluated it. For the EvaluationResult data type, Config supports only the COMPLIANT, NON_COMPLIANT, and NOT_APPLICABLE values. Config does not support the INSUFFICIENT_DATA value for the EvaluationResult data type. (COMPLIANT, NON_COMPLIANT, NOT_APPLICABLE, INSUFFICIENT_DATA)
config_rule_invoked_timestring (date-time)The time when the Config rule evaluated the Amazon Web Services resource.
evaluation_result_identifierobjectUniquely identifies the evaluation result.
result_recorded_timestring (date-time)The time when Config recorded the evaluation result.
result_tokenstringAn encrypted token that associates an evaluation with an Config rule. The token identifies the rule, the Amazon Web Services resource being evaluated, and the event that triggered the evaluation.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
get_compliance_details_by_resourceselectregionReturns the evaluation results for the specified Amazon Web Services resource. The results indicate which Config rules were used to evaluate the resource, when each rule was last invoked, and whether the resource complies with each rule.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
regionstringAWS region (default: us-east-1)

SELECT examples

Returns the evaluation results for the specified Amazon Web Services resource. The results indicate which Config rules were used to evaluate the resource, when each rule was last invoked, and whether the resource complies with each rule.

SELECT
annotation,
compliance_type,
config_rule_invoked_time,
evaluation_result_identifier,
result_recorded_time,
result_token
FROM aws.config.compliance_details_by_resources
WHERE region = '{{ region }}' -- required
;