Export Configuration - Amazon Macie

Export Configuration

The Export Configuration resource provides settings for storing data classification results in an Amazon Simple Storage Service (Amazon S3) bucket. A data classification result, also referred to as a sensitive data discovery result, is a record that logs details about the analysis of each Amazon S3 object that you configure a classification job to analyze. This includes objects that don't contain sensitive data, and therefore don't produce a finding, and objects that Amazon Macie can't analyze due to issues such as permissions settings. Macie automatically creates these records for each (and every) classification job that you create and run. You can configure Macie to store these records in an S3 bucket that you specify, and encrypt them using an AWS Key Management Service (AWS KMS) key that you also specify.

If you use Macie in multiple AWS Regions, you need to configure these settings for each Region in which you use Macie. If you prefer to store all classification results for all Regions in one S3 bucket, you can do this by specifying the same bucket, located in one specific Region, for each Region in which you use Macie.

You can use the Export Configuration resource to create, retrieve information about, or update settings for storing data classification results in an S3 bucket.

URI

/classification-export-configuration

HTTP Methods

GET

Operation ID: GetClassificationExportConfiguration

Retrieves the configuration settings for storing data classification results.

Responses
Status Code Response Model Description
200 GetClassificationExportConfigurationResponse

The request succeeded.

400 ValidationException

The request failed because it contains a syntax error.

402 ServiceQuotaExceededException

The request failed because fulfilling the request would exceed one or more service quotas for your account.

403 AccessDeniedException

The request was denied because you don't have sufficient access to the specified resource.

404 ResourceNotFoundException

The request failed because the specified resource wasn't found.

409 ConflictException

The request failed because it conflicts with the current state of the specified resource.

429 ThrottlingException

The request failed because you sent too many requests during a certain amount of time.

500 InternalServerException

The request failed due to an unknown internal server error, exception, or failure.

PUT

Operation ID: PutClassificationExportConfiguration

Creates or updates the configuration settings for storing data classification results.

Responses
Status Code Response Model Description
200 PutClassificationExportConfigurationResponse

The request succeeded.

400 ValidationException

The request failed because it contains a syntax error.

402 ServiceQuotaExceededException

The request failed because fulfilling the request would exceed one or more service quotas for your account.

403 AccessDeniedException

The request was denied because you don't have sufficient access to the specified resource.

404 ResourceNotFoundException

The request failed because the specified resource wasn't found.

409 ConflictException

The request failed because it conflicts with the current state of the specified resource.

429 ThrottlingException

The request failed because you sent too many requests during a certain amount of time.

500 InternalServerException

The request failed due to an unknown internal server error, exception, or failure.

Schemas

Request Bodies

Example PUT

{ "configuration": { "s3Destination": { "bucketName": "string", "kmsKeyArn": "string", "keyPrefix": "string" } } }

Response Bodies

Example GetClassificationExportConfigurationResponse

{ "configuration": { "s3Destination": { "bucketName": "string", "kmsKeyArn": "string", "keyPrefix": "string" } } }

Example PutClassificationExportConfigurationResponse

{ "configuration": { "s3Destination": { "bucketName": "string", "kmsKeyArn": "string", "keyPrefix": "string" } } }

Example ValidationException

{ "message": "string" }

Example ServiceQuotaExceededException

{ "message": "string" }

Example AccessDeniedException

{ "message": "string" }

Example ResourceNotFoundException

{ "message": "string" }

Example ConflictException

{ "message": "string" }

Example ThrottlingException

{ "message": "string" }

Example InternalServerException

{ "message": "string" }

Properties

AccessDeniedException

Provides information about an error that occurred due to insufficient access to a specified resource.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

ClassificationExportConfiguration

Specifies where to store data classification results, and the encryption settings to use when storing results in that location. Currently, you can store classification results only in an S3 bucket.

Property Type Required Description
s3Destination

S3Destination

False

The S3 bucket to store data classification results in, and the encryption settings to use when storing results in that bucket.

ConflictException

Provides information about an error that occurred due to a versioning conflict for a specified resource.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

GetClassificationExportConfigurationResponse

Provides information about the current configuration settings for storing data classification results.

Property Type Required Description
configuration

ClassificationExportConfiguration

False

The location where data classification results are stored, and the encryption settings that are used when storing results in that location.

InternalServerException

Provides information about an error that occurred due to an unknown internal server error, exception, or failure.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

PutClassificationExportConfigurationRequest

Specifies where to store data classification results, and the encryption settings to use when storing results in that location. Currently, you can store classification results only in an S3 bucket.

Property Type Required Description
configuration

ClassificationExportConfiguration

True

The location to store data classification results in, and the encryption settings to use when storing results in that location.

PutClassificationExportConfigurationResponse

Provides information about updated settings for storing data classification results.

Property Type Required Description
configuration

ClassificationExportConfiguration

False

The location where the data classification results are stored, and the encryption settings that are used when storing results in that location.

ResourceNotFoundException

Provides information about an error that occurred because a specified resource wasn't found.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

S3Destination

Specifies an S3 bucket to store data classification results in, and the encryption settings to use when storing results in that bucket.

Property Type Required Description
bucketName

string

True

The name of the bucket.

kmsKeyArn

string

True

The Amazon Resource Name (ARN) of the AWS Key Management Service (AWS KMS) customer master key (CMK) to use for encryption of the results. This must be the ARN of an existing CMK that's in the same AWS Region as the bucket.

keyPrefix

string

False

The path prefix to use in the path to the location in the bucket. This prefix specifies where to store classification results in the bucket.

ServiceQuotaExceededException

Provides information about an error that occurred due to one or more service quotas for an account.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

ThrottlingException

Provides information about an error that occurred because too many requests were sent during a certain amount of time.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

ValidationException

Provides information about an error that occurred due to a syntax error in a request.

Property Type Required Description
message

string

False

The explanation of the error that occurred.

See Also

For more information about using this API in one of the language-specific AWS SDKs and references, see the following:

GetClassificationExportConfiguration

PutClassificationExportConfiguration