AWS CloudFormation
User Guide (Version )

AWS::GuardDuty::Filter

The AWS::GuardDuty::Filter resource specifies a new filter defined by the provided findingCriteria.

Syntax

To declare this entity in your AWS CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::GuardDuty::Filter", "Properties" : { "Action" : String, "Description" : String, "DetectorId" : String, "FindingCriteria" : FindingCriteria, "Name" : String, "Rank" : Integer } }

YAML

Type: AWS::GuardDuty::Filter Properties: Action: String Description: String DetectorId: String FindingCriteria: FindingCriteria Name: String Rank: Integer

Properties

Action

Specifies the action that is to be applied to the findings that match the filter.

Required: Yes

Type: String

Update requires: No interruption

Description

The description of the filter.

Required: Yes

Type: String

Update requires: No interruption

DetectorId

The ID of the detector to associate the Filter with.

Required: Yes

Type: String

Update requires: Replacement

FindingCriteria

Represents the criteria to be used in the filter for querying findings.

Required: Yes

Type: FindingCriteria

Update requires: No interruption

Name

The name of the filter.

Required: No

Type: String

Update requires: Replacement

Rank

Specifies the position of the filter in the list of current filters. Also specifies the order in which this filter is applied to the findings.

Required: Yes

Type: Integer

Update requires: No interruption

Return Values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the name of the filter, such as SampleFilter.

For more information about using the Ref function, see Ref.

Examples

Declare a Filter Resource

The following example shows how to declare a GuardDuty Filter resource:

JSON

{ "Type": "AWS::GuardDuty::Filter", "Properties": { "Action": "ARCHIVE", "Description": "SampleFilter", "DetectorId": "a12abc34d567e8fa901bc2d34e56789f0", "FindingCriteria": { "Criterion": { "updatedAt": { "Gte": 0 } } }, "Rank": 1, "Name": "SampleFilter" } }

YAML

Type: "AWS::GuardDuty::Filter" Properties: Action : "ARCHIVE" Description : "SampleFilter" DetectorId : "a12abc34d567e8fa901bc2d34e56789f0" FindingCriteria : Criterion: "updatedAt": Gte: 0 Rank : 1 Name : "SampleFilter"