Skip to main content

protection_groups

Creates, updates, deletes, gets or lists a protection_groups resource.

Overview

Nameprotection_groups
TypeResource
Idaws.shield.protection_groups

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
aggregationstringDefines how Shield combines resource data for the group in order to detect, mitigate, and report events. Sum - Use the total traffic across the group. This is a good choice for most cases. Examples include Elastic IP addresses for EC2 instances that scale manually or automatically. Mean - Use the average of the traffic across the group. This is a good choice for resources that share traffic uniformly. Examples include accelerators and load balancers. Max - Use the highest traffic from each resource. This is useful for resources that don't share traffic and for resources that share that traffic in a non-uniform way. Examples include Amazon CloudFront distributions and origin resources for CloudFront distributions. (SUM, MEAN, MAX)
membersarrayThe ARNs (Amazon Resource Names) of the resources to include in the protection group. You must set this when you set Pattern to ARBITRARY and you must not set it for any other Pattern setting.
patternstringThe criteria to use to choose the protected resources for inclusion in the group. You can include all resources that have protections, provide a list of resource ARNs (Amazon Resource Names), or include all resources of a specified resource type. (ALL, ARBITRARY, BY_RESOURCE_TYPE)
protection_group_arnstringThe ARN (Amazon Resource Name) of the protection group. (pattern: <code>^arn:aws.*</code>)
protection_group_idstringThe name of the protection group. You use this to identify the protection group in lists and to manage the protection group, for example to update, delete, or describe it. (pattern: <code>[a-zA-Z0-9\-]*</code>)
resource_typestringThe resource type to include in the protection group. All protected resources of this type are included in the protection group. You must set this when you set Pattern to BY_RESOURCE_TYPE and you must not set it for any other Pattern setting. (CLOUDFRONT_DISTRIBUTION, ROUTE_53_HOSTED_ZONE, ELASTIC_IP_ALLOCATION, CLASSIC_LOAD_BALANCER, APPLICATION_LOAD_BALANCER, GLOBAL_ACCELERATOR)

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
describe_protection_groupselectregionReturns the specification for the specified protection group.
list_protection_groupsselectregionRetrieves ProtectionGroup objects for the account. You can retrieve all protection groups or you can provide filtering criteria and retrieve just the subset of protection groups that match the criteria.
create_protection_groupinsertregion, ProtectionGroupId, Aggregation, PatternCreates a grouping of protected resources so they can be handled as a collective. This resource grouping improves the accuracy of detection and reduces false positives.
update_protection_groupupdateregion, ProtectionGroupId, Aggregation, PatternUpdates an existing protection group. A protection group is a grouping of protected resources so they can be handled as a collective. This resource grouping improves the accuracy of detection and reduces false positives.
delete_protection_groupdeleteregionRemoves the specified protection group.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
regionstringAWS region (default: us-east-1)

SELECT examples

Returns the specification for the specified protection group.

SELECT
aggregation,
members,
pattern,
protection_group_arn,
protection_group_id,
resource_type
FROM aws.shield.protection_groups
WHERE region = '{{ region }}' -- required
;

INSERT examples

Creates a grouping of protected resources so they can be handled as a collective. This resource grouping improves the accuracy of detection and reduces false positives.

INSERT INTO aws.shield.protection_groups (
ProtectionGroupId,
Aggregation,
Pattern,
ResourceType,
Members,
Tags,
region
)
SELECT
'{{ ProtectionGroupId }}' /* required */,
'{{ Aggregation }}' /* required */,
'{{ Pattern }}' /* required */,
'{{ ResourceType }}',
'{{ Members }}',
'{{ Tags }}',
'{{ region }}'
;

UPDATE examples

Updates an existing protection group. A protection group is a grouping of protected resources so they can be handled as a collective. This resource grouping improves the accuracy of detection and reduces false positives.

UPDATE aws.shield.protection_groups
SET
ProtectionGroupId = '{{ ProtectionGroupId }}',
Aggregation = '{{ Aggregation }}',
Pattern = '{{ Pattern }}',
ResourceType = '{{ ResourceType }}',
Members = '{{ Members }}'
WHERE
region = '{{ region }}' --required
AND ProtectionGroupId = '{{ ProtectionGroupId }}' --required
AND Aggregation = '{{ Aggregation }}' --required
AND Pattern = '{{ Pattern }}' --required;

DELETE examples

Removes the specified protection group.

DELETE FROM aws.shield.protection_groups
WHERE region = '{{ region }}' --required
;