Amazon Relational Database Service
Command Line Interface Reference (API Version 2014-10-31)


The Amazon RDS Command Line Interface (RDS CLI) has been deprecated. Instead, use the AWS CLI for RDS. To learn how to download and use the AWS CLI, see AWS Command Line Interface User Guide. For RDS commands available in the AWS CLI, see AWS CLI Reference for Amazon RDS.

The AWS CLI does not currently support the DownloadCompleteDBLogFile REST API action. To download an entire log file at once, rather than in parts using the download-db-log-file-portion command, use the last published RDS CLI and the rds-download-db-logfile command.


Returns information about all database security groups for an account if no database security group name is supplied, or displays information about a specific named database security group.


rds-describe-db-security-groups [db-security-group-name]

[General Options]


Name Description Required


Database security group name.

This parameter is the default parameter and can be passed as the first value in the command and without a parameter name, for example: rds-describe-db-security-groups my-db-security-group-name.

Type: String

Default: None



The command returns the following information:


Output values list the possible values returned by CLI commands. Not all values are returned for every call to a command. If a value is null or empty, it will not be included in the command output. For example, CLI commands to create or restore a DB instance will not return the Endpoint Address value because that value is null until the DB instance has finished being created or restored.

  • Name—Security group name

  • Description—Description of the database security group

  • Amazon EC2 Group Name—EC2 security group name

  • Amazon EC2 Owner Id—EC2 security group owner

  • Status—Status of security group authorization. Valid values: adding | active | removing

  • IP Range—the CIDR IP range allowed access to the security group

  • Status—Status of authorization for the IP Range. Valid values: authorizing | authorized | revoking


Get a Description of All Security Groups

This example returns a description of all database security groups for the account, with column headers.

PROMPT> rds-describe-db-security-groups -H SECGROUP Name Description SECGROUP Default Default EC2-SECGROUP EC2 Group Name EC2 Owner Id Status EC2-SECGROUP mytestgroup 210987654321 authorized IP-RANGE IP Range Status IP-RANGE authorized IP-RANGE authorized