AWS Security Lake

Amazon Security Lake is a fully managed security data lake service.

IT Services · Amazon - Security Lake

Details

IDAWS Security Lake
ProviderAmazon
CategoryIT Services
From Version6.10.0
Docker Imagedemisto/boto3py3:1.0.0.10221838
Supported ModulesAgentix XSIAM

README

Amazon Security Lake is a fully managed security data lake service.
This integration was integrated and tested with version 1.34.20 of AWS Security Lake SDK (boto3).

Configure Amazon Security Lake in Cortex

Parameter Description Required
Name User name True
Role Arn Role ARN False
Role Session Name Role Session Name False
Role Session Duration Role Session Duration False
AWS Default Region AWS Default Region False
Access Key Access Key False
Secret Key Secret Key False
Timeout The time in seconds until a timeout exception is reached. You can specify just the read timeout (for example 60) or also the connect timeout followed after a comma (for example 60,10). If a connect timeout is not specified, a default of 10 second will be used. False
Retries The maximum number of retry attempts when connection or throttling errors are encountered. Set to 0 to disable retries. The default value is 5 and the limit is 10. Note: Increasing the number of retries will increase the execution time. False
Trust any certificate (not secure)   False
Use system proxy settings   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

aws-security-lake-query-execute


Execute a new query, wait for the query to complete (using polling), and return query’s execution information, and query’s results (if successful). Either ‘OutputLocation’ or ‘WorkGroup’ must be specified for the query to run.

Base Command

aws-security-lake-query-execute

Input

Argument Name Description Required
query_string The SQL query statements to be executed. Required
query_limit A limit (number) to use for the query. If the keyword ‘LIMIT’ exists within ‘QueryString’, this parameter will be ignored. Default is 50. Optional
client_request_token A unique case-sensitive string used to ensure the request to create the query is idempotent (executes only once). If another StartQueryExecution request is received, the same response is returned and another query is not created. Optional
database The name of the database. Optional
output_location The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/. Optional
encryption_option Indicates whether Amazon S3 server-side encryption with Amazon S3-managed keys (SSE-S3 ), server-side encryption with KMS-managed keys (SSE-KMS ), or client-side encryption with KMS-managed keys (CSE-KMS) is used. Optional
kms_key For SSE-KMS and CSE-KMS , this is the KMS key ARN or ID. Optional
work_group The name of the workgroup in which the query is being started. Optional
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
region The AWS region. If not specified, the default region will be used. Optional
QueryExecutionId ID of the newly created query. Used internally for polling. Optional
hide_polling_output   Optional

Context Output

Path Type Description
AWS.SecurityLake.Query.QueryExecutionId String The unique identifier for each query execution.
AWS.SecurityLake.Query.Query String The SQL query statements which the query execution ran.
AWS.SecurityLake.Query.StatementType String The type of query statement that was run.
AWS.SecurityLake.Query.ResultConfiguration.OutputLocation String The location in Amazon S3 where your query and calculation results are stored, such as ‘s3://path/to/query/bucket/’.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption String If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey String For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner String The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption String The Amazon S3 canned ACL that Athena should specify when storing query results.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled Boolean True if previous query results can be reused when the query is run; otherwise, false. The default is false.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes Number Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
AWS.SecurityLake.Query.QueryExecutionContext.Database String The name of the database used in the query execution.
AWS.SecurityLake.Query.QueryExecutionContext.Catalog String The name of the data catalog used in the query execution.
AWS.SecurityLake.Query.Status.State String The state of the query execution.
AWS.SecurityLake.Query.Status.StateChangeReason String Further detail about the status of the query.
AWS.SecurityLake.Query.Status.SubmissionDateTime String The date and time that the query was submitted.
AWS.SecurityLake.Query.Status.CompletionDateTime String The date and time that the query completed.
AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory Number An integer value that specifies the category of a query failure error.
AWS.SecurityLake.Query.Status.AthenaError.ErrorType Number An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
AWS.SecurityLake.Query.Status.AthenaError.Retryable Boolean True if the query might succeed if resubmitted.
AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage String Contains a short description of the error that occurred.
AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis Number The number of milliseconds that the query took to execute.
AWS.SecurityLake.Query.Statistics.DataScannedInBytes Number The number of bytes in the data that was queried.
AWS.SecurityLake.Query.Statistics.DataManifestLocation String The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis Number The number of milliseconds that Athena took to run the query.
AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis Number The number of milliseconds that the query was in your query queue waiting for resources.
AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis Number The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis Number The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis Number The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult Boolean True if a previous query result was reused; false if the result was generated from a new run of the query.
AWS.SecurityLake.Query.WorkGroup String The name of the workgroup in which the query ran.
AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion String The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion String The engine version on which the query runs.
AWS.SecurityLake.Query.ExecutionParameters List A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
AWS.SecurityLake.Query.SubstatementType String The type of query statement that was run.
AWS.SecurityLake.QueryResults List List of query results.

aws-security-lake-data-catalogs-list


Lists the data catalogs in the current Amazon Web Services account.

Base Command

aws-security-lake-data-catalogs-list

Input

Argument Name Description Required
work_group The name of the workgroup. Required if making an IAM Identity Center request. Optional
region The AWS region. If not specified, the default region will be used. Optional
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
limit Specifies the maximum number of data catalogs to return. Optional
next_token Specifies the maximum number of data catalogs to return. Optional

Context Output

Path Type Description
AWS.SecurityLake.Catalog.CatalogName String The name of the data catalog.
AWS.SecurityLake.Catalog.Type String The data catalog type.
AWS.SecurityLake.CatalogNextToken String A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.

aws-security-lake-databases-list


Lists the databases in the specified data catalog.

Base Command

aws-security-lake-databases-list

Input

Argument Name Description Required
catalog_name The name of the data catalog that contains the databases to return. Required
work_group The name of the workgroup for which the metadata is being fetched. Required if requesting an IAM Identity Center enabled Glue Data Catalog. Optional
region The AWS region. If not specified, the default region will be used. Optional
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
limit Specifies the maximum number of results to return. Optional
next_token A token generated by the SecurityLake. service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call. Optional

Context Output

Path Type Description
AWS.SecurityLake.Database.Name String The name of the database.
AWS.SecurityLake.Database.Description String An optional description of the database.
AWS.SecurityLake.Database.Parameters List A set of custom key/value pairs.
AWS.SecurityLake.DatabaseNextToken String A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.

Command Example

!aws-security-lake-databases-list catalog_name=Test

aws-security-lake-table-metadata-list


Lists the metadata for the tables in the specified data catalog database.

Base Command

aws-security-lake-table-metadata-list

Input

Argument Name Description Required
catalog_name The name of the data catalog that contains the databases to return. Required
database_name The name of the database for which table metadata should be returned. Required
expression A regex filter that pattern-matches table names. If no expression is supplied, metadata for all tables are listed. Optional
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
limit Specifies the maximum number of results to return. Optional
next_token A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call. Optional
work_group The name of the workgroup for which the metadata is being fetched. Required if requesting an IAM Identity Center enabled Glue Data Catalog. Optional

Context Output

Path Type Description
AWS.SecurityLake.TableMetadata.Name String The name of the table.
AWS.SecurityLake.TableMetadata.CreateTime Date The time that the table was created.
AWS.SecurityLake.TableMetadata.LastAccessTime Date The last time the table was accessed.
AWS.SecurityLake.TableMetadata.TableType String The type of table. In Athena, only EXTERNAL_TABLE is supported.
AWS.SecurityLake.TableMetadata.Columns.Name String The name of the column.
AWS.SecurityLake.TableMetadata.Columns.Type String The data type of the column.
AWS.SecurityLake.TableMetadata.Columns.Comment String Optional information about the column.
AWS.SecurityLake.TableMetadata.PartitionKeys.Name String The name of the column.
AWS.SecurityLake.TableMetadata.PartitionKeys.Type String The data type of the column.
AWS.SecurityLake.TableMetadata.PartitionKeys.Comment String Optional information about the column.
AWS.SecurityLake.TableMetadata.Parameters List A set of custom key/value pairs for table properties.
AWS.SecurityLake.TableMetadataNextToken String A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.

Command Example

!aws-security-lake-table-metadata-list catalog_name=Test database_name=test

aws-security-lake-user-mfalogin-query


Runs query that takes a provided username and queries the AWS Security Lake for MFA login attempts (Success/Failed) associated with the user’s account, using AWS CloudTrail logs.

Base Command

aws-security-lake-user-mfalogin-query

Input

Argument Name Description Required
database The database to run the query against. Required
table The table to run the query against. Required
user_name The username to search for MFA login attempts. Required
output_location The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/. Required
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
region The AWS region. If not specified, the default region will be used. Optional
query_limit A limit (number) to use for the query. If the keyword ‘LIMIT’ exists within ‘QueryString’, this parameter will be ignored. Optional

Context Output

Path Type Description
AWS.SecurityLake.Query.QueryExecutionId String The unique identifier for each query execution.
AWS.SecurityLake.Query.Query String The SQL query statements which the query execution ran.
AWS.SecurityLake.Query.StatementType String The type of query statement that was run.
AWS.SecurityLake.Query.ResultConfiguration.OutputLocation String The location in Amazon S3 where your query and calculation results are stored, such as ‘s3://path/to/query/bucket/’.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption String If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey String For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner String The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption String The Amazon S3 canned ACL that Athena should specify when storing query results.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled Boolean True if previous query results can be reused when the query is run; otherwise, false. The default is false.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes Number Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
AWS.SecurityLake.Query.QueryExecutionContext.Database String The name of the database used in the query execution.
AWS.SecurityLake.Query.QueryExecutionContext.Catalog String The name of the data catalog used in the query execution.
AWS.SecurityLake.Query.Status.State String The state of the query execution.
AWS.SecurityLake.Query.Status.StateChangeReason String Further detail about the status of the query.
AWS.SecurityLake.Query.Status.SubmissionDateTime String The date and time that the query was submitted.
AWS.SecurityLake.Query.Status.CompletionDateTime String The date and time that the query completed.
AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory Number An integer value that specifies the category of a query failure error.
AWS.SecurityLake.Query.Status.AthenaError.ErrorType Number An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
AWS.SecurityLake.Query.Status.AthenaError.Retryable Boolean True if the query might succeed if resubmitted.
AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage String Contains a short description of the error that occurred.
AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis Number The number of milliseconds that the query took to execute.
AWS.SecurityLake.Query.Statistics.DataScannedInBytes Number The number of bytes in the data that was queried.
AWS.SecurityLake.Query.Statistics.DataManifestLocation String The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis Number The number of milliseconds that Athena took to run the query.
AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis Number The number of milliseconds that the query was in your query queue waiting for resources.
AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis Number The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis Number The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis Number The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult Boolean True if a previous query result was reused; false if the result was generated from a new run of the query.
AWS.SecurityLake.Query.WorkGroup String The name of the workgroup in which the query ran.
AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion String The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion String The engine version on which the query runs.
AWS.SecurityLake.Query.ExecutionParameters List A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
AWS.SecurityLake.Query.SubstatementType String The type of query statement that was run.
AWS.SecurityLake.MfaLoginQueryResults List List of query results.

Command Example

!aws-security-lake-user-mfalogin-query table=Test database=test user_name=123 output_location=s3://path/to/query/bucket/

aws-security-lake-source-ip-query


Runs a query that takes a provided source IP address and queries the AWS Security Lake for console login attempts (Success/Failed) associated with the IP address, using AWS CloudTrail logs.

Base Command

aws-security-lake-source-ip-query

Input

Argument Name Description Required
database The database to run the query against. Required
table The table to run the query against. Required
ip_src The source IP address to search for console login attempts. Required
output_location The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/. Required
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
region The AWS region. If not specified, the default region will be used. Optional
query_limit A limit (number) to use for the query. If the keyword ‘LIMIT’ exists within ‘QueryString’, this parameter will be ignored. Optional

Context Output

Path Type Description
AWS.SecurityLake.Query.QueryExecutionId String The unique identifier for each query execution.
AWS.SecurityLake.Query.Query String The SQL query statements which the query execution ran.
AWS.SecurityLake.Query.StatementType String The type of query statement that was run.
AWS.SecurityLake.Query.ResultConfiguration.OutputLocation String The location in Amazon S3 where your query and calculation results are stored, such as ‘s3://path/to/query/bucket/’.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption String If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey String For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner String The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption String The Amazon S3 canned ACL that Athena should specify when storing query results.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled Boolean True if previous query results can be reused when the query is run; otherwise, false. The default is false.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes Number Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
AWS.SecurityLake.Query.QueryExecutionContext.Database String The name of the database used in the query execution.
AWS.SecurityLake.Query.QueryExecutionContext.Catalog String The name of the data catalog used in the query execution.
AWS.SecurityLake.Query.Status.State String The state of the query execution.
AWS.SecurityLake.Query.Status.StateChangeReason String Further detail about the status of the query.
AWS.SecurityLake.Query.Status.SubmissionDateTime String The date and time that the query was submitted.
AWS.SecurityLake.Query.Status.CompletionDateTime String The date and time that the query completed.
AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory Number An integer value that specifies the category of a query failure error.
AWS.SecurityLake.Query.Status.AthenaError.ErrorType Number An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
AWS.SecurityLake.Query.Status.AthenaError.Retryable Boolean True if the query might succeed if resubmitted.
AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage String Contains a short description of the error that occurred.
AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis Number The number of milliseconds that the query took to execute.
AWS.SecurityLake.Query.Statistics.DataScannedInBytes Number The number of bytes in the data that was queried.
AWS.SecurityLake.Query.Statistics.DataManifestLocation String The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis Number The number of milliseconds that Athena took to run the query.
AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis Number The number of milliseconds that the query was in your query queue waiting for resources.
AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis Number The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis Number The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis Number The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult Boolean True if a previous query result was reused; false if the result was generated from a new run of the query.
AWS.SecurityLake.Query.WorkGroup String The name of the workgroup in which the query ran.
AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion String The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion String The engine version on which the query runs.
AWS.SecurityLake.Query.ExecutionParameters List A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
AWS.SecurityLake.Query.SubstatementType String The type of query statement that was run.
AWS.SecurityLake.SourceIPQueryResults List List of query results.

Command Example

!aws-security-lake-source-ip-query table=Test database=test ip_src=1.2.3.4 output_location=s3://path/to/query/bucket/

aws-security-lake-guardduty-activity-query


This command is used to search for Guard Duty logs for any criticality level activity.

Base Command

aws-security-lake-guardduty-activity-query

Input

Argument Name Description Required
database The database to run the query against. Required
table The table to run the query against. Required
severity The severity of searchingto search related events for. Possible values are: 0-Unknown, 1-Informational, 2-Low, 3-Medium, 4-High, 5-Critical, 6-Fatal, 99-Other. Required
output_location The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/. Required
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
region The AWS region. If not specified, the default region will be used. Optional
query_limit A limit (number) to use for the query. If the keyword ‘LIMIT’ exists within ‘QueryString’, this parameter will be ignored. Optional

Context Output

Path Type Description
AWS.SecurityLake.Query.QueryExecutionId String The unique identifier for each query execution.
AWS.SecurityLake.Query.Query String The SQL query statements which the query execution ran.
AWS.SecurityLake.Query.StatementType String The type of query statement that was run.
AWS.SecurityLake.Query.ResultConfiguration.OutputLocation String The location in Amazon S3 where your query and calculation results are stored, such as ‘s3://path/to/query/bucket/’.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption String If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey String For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner String The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption String The Amazon S3 canned ACL that Athena should specify when storing query results.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled Boolean True if previous query results can be reused when the query is run; otherwise, false. The default is false.
AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes Number Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
AWS.SecurityLake.Query.QueryExecutionContext.Database String The name of the database used in the query execution.
AWS.SecurityLake.Query.QueryExecutionContext.Catalog String The name of the data catalog used in the query execution.
AWS.SecurityLake.Query.Status.State String The state of the query execution.
AWS.SecurityLake.Query.Status.StateChangeReason String Further detail about the status of the query.
AWS.SecurityLake.Query.Status.SubmissionDateTime String The date and time that the query was submitted.
AWS.SecurityLake.Query.Status.CompletionDateTime String The date and time that the query completed.
AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory Number An integer value that specifies the category of a query failure error.
AWS.SecurityLake.Query.Status.AthenaError.ErrorType Number An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
AWS.SecurityLake.Query.Status.AthenaError.Retryable Boolean True if the query might succeed if resubmitted.
AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage String Contains a short description of the error that occurred.
AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis Number The number of milliseconds that the query took to execute.
AWS.SecurityLake.Query.Statistics.DataScannedInBytes Number The number of bytes in the data that was queried.
AWS.SecurityLake.Query.Statistics.DataManifestLocation String The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis Number The number of milliseconds that Athena took to run the query.
AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis Number The number of milliseconds that the query was in your query queue waiting for resources.
AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis Number The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis Number The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis Number The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult Boolean True if a previous query result was reused; false if the result was generated from a new run of the query.
AWS.SecurityLake.Query.WorkGroup String The name of the workgroup in which the query ran.
AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion String The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion String The engine version on which the query runs.
AWS.SecurityLake.Query.ExecutionParameters List A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
AWS.SecurityLake.Query.SubstatementType String The type of query statement that was run.
AWS.SecurityLake.GuardDutyActivityQueryResults List List of query results.

Command Example

!aws-security-lake-guardduty-activity-query table=Test database=test severity=0-Unknown output_location=s3://path/to/query/bucket/

aws-security-lake-data-sources-list


Retrieves a snapshot of the current region, including whether Amazon Security Lake is enabled for those accounts and which sources Security Lake is collecting data from.
In order to run this command the user must have ‘securitylake’ permissions.

Base Command

aws-security-lake-data-sources-list

Input

Argument Name Description Required
accounts The Amazon Web Services account ID for which a static snapshot of the current Amazon Web Services Region, including enabled accounts and log sources, is retrieved. Optional
limit Specifies the maximum number of results to return. Optional
next_token Lists if there are more results available. The value of nextToken is a unique pagination token for each page. Repeat the call using the returned token to retrieve the next page. Keep all other arguments unchanged. Optional
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
region The AWS region. If not specified, the default region will be used. Optional
query_limit A limit (number) to use for the query. If the keyword ‘LIMIT’ exists within ‘QueryString’, this parameter will be ignored. Optional

Context Output

Path Type Description
AWS.SecurityLake.DataLakeSource.DataLakeArn String The Amazon Resource Name (ARN) created by you to provide to the subscriber.
AWS.SecurityLake.DataLakeSource.DataLakeSources.account String The ID of the Security Lake account for which logs are collected.
AWS.SecurityLake.DataLakeSource.DataLakeSources.eventClasses List The Open Cybersecurity Schema Framework (OCSF) event classes which describes the type of data that the custom source will send to Security Lake.
AWS.SecurityLake.DataLakeSource.DataLakeSources.sourceName String The supported Amazon Web Services from which logs and events are collected. Amazon Security Lake supports log and event collection for natively supported Amazon Web Services.
AWS.SecurityLake.DataLakeSource.DataLakeSources.sourceStatuses.resource String Defines the path in which the stored logs are available which has information on your systems, applications, and services.
AWS.SecurityLake.DataLakeSource.DataLakeSources.sourceStatuses.status String The health status of services, including error codes and patterns.
AWS.SecurityLake.DataLakeSourceNextToken String Lists if there are more results available. The value of nextToken is a unique pagination token for each page. Repeat the call using the returned token to retrieve the next page. Keep all other arguments unchanged.

Command Example

!aws-security-lake-data-sources-list

aws-security-lake-data-lakes-list


Retrieves the Amazon Security Lake configuration object for the specified Amazon Web Services Regions.
In order to run this command the user must have ‘securitylake’ permissions.

Base Command

aws-security-lake-data-lakes-list

Input

Argument Name Description Required
regions The list of regions where Security Lake is enabled. Optional
roleArn The Amazon Resource Name (ARN) of the role to assume. Optional
roleSessionName An identifier for the assumed role session. Optional
roleSessionDuration The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role. Optional
region The AWS region. If not specified, the default region will be used. Optional
query_limit A limit (number) to use for the query. If the keyword ‘LIMIT’ exists within ‘QueryString’, this parameter will be ignored. Optional

Context Output

Path Type Description
AWS.SecurityLake.createStatus String Retrieves the status of the configuration operation for an account in Amazon Security Lake.
AWS.SecurityLake.dataLakeArn String The Amazon Resource Name (ARN) created by you to provide to the subscriber.
AWS.SecurityLake.encryptionConfiguration.kmsKeyId String The ID of the KMS encryption key used by Amazon Security Lake to encrypt the Security Lake object.
AWS.SecurityLake.lifecycleConfiguration.expiration.days Number Number of days before data expires in the Amazon Security Lake object.
AWS.SecurityLake.lifecycleConfiguration.transitions.days Number Number of days before data transitions to a different S3 Storage Class in the Amazon Security Lake object.
AWS.SecurityLake.lifecycleConfiguration.transitions.storageClass String The range of storage classes that you can choose from based on the data access, resiliency, and cost requirements of your workloads.
AWS.SecurityLake.region String The Amazon Web Services regions where Security Lake is enabled.
AWS.SecurityLake.replicationConfiguration.regions String Replication enables automatic, asynchronous copying of objects across Amazon S3 buckets.
AWS.SecurityLake.replicationConfiguration.roleArn String Replication settings for the Amazon S3 buckets. This parameter uses the Identity and Access Management (IAM) role you created that is managed by Security Lake, to ensure the replication setting is correct.
AWS.SecurityLake.s3BucketArn String The ARN for the Amazon Security Lake Amazon S3 bucket.
AWS.SecurityLake.updateStatus.exception.code String The reason code for the exception of the last UpdateDataLake or DeleteDataLake API request.
AWS.SecurityLake.updateStatus.exception.reason String The reason for the exception of the last UpdateDataLake or DeleteDataLake API request.
AWS.SecurityLake.updateStatus.requestId String The unique ID for the last UpdateDataLake or DeleteDataLake API request.
AWS.SecurityLake.updateStatus.status String The status of the last UpdateDataLake or DeleteDataLake API request that was requested.

Command Example

!aws-security-lake-data-lakes-list

Configuration parameters

  • roleArn — Role ARN
  • roleSessionName — Role Session Name
  • sessionDuration — Role Session Duration
  • defaultRegion — AWS Default Region (required)
  • credentials — Access Key
  • timeout — Timeout
  • retries — Retries
  • sts_regional_endpoint — AWS STS Regional Endpoints
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (9)

  • aws-security-lake-data-catalogs-list

    Lists the data catalogs in the current Amazon Web Services account.

  • aws-security-lake-data-lakes-list

    Retrieves the Amazon Security Lake configuration object for the specified Amazon Web Services Regions. In order to run this command the user must have 'securitylake' permissions.

  • aws-security-lake-data-sources-list

    Retrieves a snapshot of the current region, including whether Amazon Security Lake is enabled for those accounts and which sources Security Lake is collecting data from. In order to run this command the user must have 'securitylake' permissions.

  • aws-security-lake-databases-list

    Lists the databases in the specified data catalog.

  • aws-security-lake-guardduty-activity-query

    This command is used to search for Guard Duty logs for any criticality level activity.

  • aws-security-lake-query-execute

    Execute a new query, wait for the query to complete (using polling), and return query's execution information, and query's results (if successful). Either 'OutputLocation' or 'WorkGroup' must be specified for the query to run.

  • aws-security-lake-source-ip-query

    Runs a query that takes a provided source IP address and queries the AWS Security Lake for console login attempts (Success/Failed) associated with the IP address, using AWS CloudTrail logs.

  • aws-security-lake-table-metadata-list

    Lists the metadata for the tables in the specified data catalog database.

  • aws-security-lake-user-mfalogin-query

    Runs query that takes a provided username and queries the AWS Security Lake for MFA login attempts (Success/Failed) associated with the user's account, using AWS CloudTrail logs.

category: IT Services
provider: Amazon
commonfields:
  id: AWS Security Lake
  version: -1
configuration:
- name: roleArn
  display: Role ARN
  required: false
  type: 0
  section: Connect
- name: roleSessionName
  display: Role Session Name
  required: false
  type: 0
  section: Connect
- name: sessionDuration
  display: Role Session Duration
  required: false
  type: 0
  section: Connect
  advanced: true
- name: defaultRegion
  display: AWS Default Region
  required: true
  type: 15
  options:
  - us-east-1
  - us-east-2
  - us-west-1
  - us-west-2
  - ca-central-1
  - eu-west-1
  - eu-central-1
  - eu-west-2
  - ap-northeast-1
  - ap-northeast-2
  - ap-southeast-1
  - ap-southeast-2
  - ap-south-1
  - sa-east-1
  - eu-north-1
  - eu-west-3
  - us-gov-east-1
  - us-gov-west-1
  section: Connect
- name: credentials
  display: Access Key
  required: false
  type: 9
  displaypassword: Secret Key
  hiddenusername: false
  section: Connect
- name: timeout
  display: Timeout
  required: false
  defaultvalue: 60,10
  type: 0
  section: Connect
  advanced: true
  additionalinfo: The time in seconds until a timeout exception is reached. You can specify just the read timeout (for example 60) or also the connect timeout followed after a comma (for example 60,10). If a connect timeout is not specified, a default of 10 second will be used.
- name: retries
  display: Retries
  required: false
  defaultvalue: 5
  type: 0
  section: Connect
  advanced: true
  additionalinfo: "The maximum number of retry attempts when connection or throttling errors are encountered. Set to 0 to disable retries. The default value is 5 and the limit is 10. Note: Increasing the number of retries will increase the execution time."
- display: AWS STS Regional Endpoints
  additionalinfo: Sets the AWS_STS_REGIONAL_ENDPOINTS environment variable to specify the AWS STS endpoint resolution logic. By default, this option is set to “legacy” in AWS. Leave empty if the environment variable is already set using server configuration.
  name: sts_regional_endpoint
  options:
  - legacy
  - regional
  type: 15
  section: Connect
  required: false
- name: insecure
  display: Trust any certificate (not secure)
  required: false
  defaultvalue: 'false'
  type: 8
  advanced: true
- name: proxy
  display: Use system proxy settings
  required: false
  defaultvalue: 'false'
  type: 8
  advanced: true
description: "Amazon Security Lake is a fully managed security data lake service."
display: Amazon Security Lake
name: AWS Security Lake
script:
  commands:
  - name: aws-security-lake-query-execute
    arguments:
    - name: query_string
      description: The SQL query statements to be executed.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: query_limit
      description: A limit (number) to use for the query. If the keyword 'LIMIT' exists within 'QueryString', this parameter will be ignored.
      required: false
      isArray: false
      defaultValue: "50"
      predefined:
      - ""
    - name: client_request_token
      description: A unique case-sensitive string used to ensure the request to create the query is idempotent (executes only once). If another StartQueryExecution request is received, the same response is returned and another query is not created.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: database
      description: The name of the database.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: output_location
      description: The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: encryption_option
      description: Indicates whether Amazon S3 server-side encryption with Amazon S3-managed keys (SSE-S3 ), server-side encryption with KMS-managed keys (SSE-KMS ), or client-side encryption with KMS-managed keys (CSE-KMS) is used.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: kms_key
      description: For SSE-KMS and CSE-KMS , this is the KMS key ARN or ID.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: work_group
      description: The name of the workgroup in which the query is being started.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
    - name: roleSessionName
      description: An identifier for the assumed role session.
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
    - name: region
      description: The AWS region. If not specified, the default region will be used.
    - name: QueryExecutionId
      hidden: true
      description: ID of the newly created query. Used internally for polling.
    - name: hide_polling_output
      hidden: true
      description: ""
    description: Execute a new query, wait for the query to complete (using polling), and return query's execution information, and query's results (if successful). Either 'OutputLocation' or 'WorkGroup' must be specified for the query to run.
    polling: true
    outputs:
    - contextPath: AWS.SecurityLake.Query.QueryExecutionId
      description: The unique identifier for each query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Query
      description: The SQL query statements which the query execution ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.StatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.OutputLocation
      description: The location in Amazon S3 where your query and calculation results are stored, such as 's3://path/to/query/bucket/'.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption
      description: If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey
      description: For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner
      description: The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption
      description: The Amazon S3 canned ACL that Athena should specify when storing query results.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled
      description: True if previous query results can be reused when the query is run; otherwise, false. The default is false.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes
      description: Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
      type: Number
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Database
      description: The name of the database used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Catalog
      description: The name of the data catalog used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.State
      description: The state of the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.StateChangeReason
      description: Further detail about the status of the query.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.SubmissionDateTime
      description: The date and time that the query was submitted.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.CompletionDateTime
      description: The date and time that the query completed.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory
      description: An integer value that specifies the category of a query failure error.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorType
      description: An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.Retryable
      description: True if the query might succeed if resubmitted.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage
      description: Contains a short description of the error that occurred.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis
      description: The number of milliseconds that the query took to execute.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataScannedInBytes
      description: The number of bytes in the data that was queried.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataManifestLocation
      description: The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis
      description: The number of milliseconds that Athena took to run the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis
      description: The number of milliseconds that the query was in your query queue waiting for resources.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis
      description: The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis
      description: The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis
      description: The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult
      description: True if a previous query result was reused; false if the result was generated from a new run of the query.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.WorkGroup
      description: The name of the workgroup in which the query ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion
      description: The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion
      description: The engine version on which the query runs.
      type: String
    - contextPath: AWS.SecurityLake.Query.ExecutionParameters
      description: A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
      type: List
    - contextPath: AWS.SecurityLake.Query.SubstatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.QueryResults
      description: List of query results.
      type: List
  - name: aws-security-lake-data-catalogs-list
    description: Lists the data catalogs in the current Amazon Web Services account.
    deprecated: false
    arguments:
    - name: work_group
      description: The name of the workgroup. Required if making an IAM Identity Center request.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: limit
      description: Specifies the maximum number of data catalogs to return.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: next_token
      description: Specifies the maximum number of data catalogs to return.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    outputs:
    - contextPath: AWS.SecurityLake.Catalog.CatalogName
      description: The name of the data catalog.
      type: String
    - contextPath: AWS.SecurityLake.Catalog.Type
      description: The data catalog type.
      type: String
    - contextPath: AWS.SecurityLake.CatalogNextToken
      description: A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.
      type: String
  - name: aws-security-lake-databases-list
    description: Lists the databases in the specified data catalog.
    deprecated: false
    arguments:
    - name: catalog_name
      description: The name of the data catalog that contains the databases to return.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: work_group
      description: The name of the workgroup for which the metadata is being fetched. Required if requesting an IAM Identity Center enabled Glue Data Catalog.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: limit
      description: Specifies the maximum number of results to return.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: next_token
      description: A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    outputs:
    - contextPath: AWS.SecurityLake.Database.Name
      description: The name of the database.
      type: String
    - contextPath: AWS.SecurityLake.Database.Description
      description: An optional description of the database.
      type: String
    - contextPath: AWS.SecurityLake.Database.Parameters
      description: A set of custom key/value pairs.
      type: List
    - contextPath: AWS.SecurityLake.DatabaseNextToken
      description: A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.
      type: String
  - name: aws-security-lake-table-metadata-list
    description: Lists the metadata for the tables in the specified data catalog database.
    deprecated: false
    arguments:
    - name: catalog_name
      description: The name of the data catalog that contains the databases to return.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: database_name
      description: The name of the database for which table metadata should be returned.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: expression
      description: A regex filter that pattern-matches table names. If no expression is supplied, metadata for all tables are listed.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: limit
      description: Specifies the maximum number of results to return.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: next_token
      description: A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: work_group
      description: The name of the workgroup for which the metadata is being fetched. Required if requesting an IAM Identity Center enabled Glue Data Catalog.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    outputs:
    - contextPath: AWS.SecurityLake.TableMetadata.Name
      description: The name of the table.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.CreateTime
      description: The time that the table was created.
      type: Date
    - contextPath: AWS.SecurityLake.TableMetadata.LastAccessTime
      description: The last time the table was accessed.
      type: Date
    - contextPath: AWS.SecurityLake.TableMetadata.TableType
      description: The type of table. In Athena, only EXTERNAL_TABLE is supported.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.Columns.Name
      description: The name of the column.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.Columns.Type
      description: The data type of the column.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.Columns.Comment
      description: Optional information about the column.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.PartitionKeys.Name
      description: The name of the column.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.PartitionKeys.Type
      description: The data type of the column.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.PartitionKeys.Comment
      description: Optional information about the column.
      type: String
    - contextPath: AWS.SecurityLake.TableMetadata.Parameters
      description: A set of custom key/value pairs for table properties.
      type: List
    - contextPath: AWS.SecurityLake.TableMetadataNextToken
      description: A token generated by the SecurityLake service that specifies where to continue pagination if a previous request was truncated. To obtain the next set of pages, pass in the NextToken from the response object of the previous page call.
      type: String
  - name: aws-security-lake-user-mfalogin-query
    description: Runs query that takes a provided username and queries the AWS Security Lake for MFA login attempts (Success/Failed) associated with the user's account, using AWS CloudTrail logs.
    deprecated: false
    arguments:
    - name: database
      description: The database to run the query against.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: table
      description: The table to run the query against.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: user_name
      description: The username to search for MFA login attempts.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: output_location
      description: The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
    - name: query_limit
      description: A limit (number) to use for the query. If the keyword 'LIMIT' exists within 'QueryString', this parameter will be ignored.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: QueryExecutionId
      hidden: true
      description: ID of the newly created query. Used internally for polling.
    - name: hide_polling_output
      hidden: true
      description: ""
    polling: true
    outputs:
    - contextPath: AWS.SecurityLake.Query.QueryExecutionId
      description: The unique identifier for each query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Query
      description: The SQL query statements which the query execution ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.StatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.OutputLocation
      description: The location in Amazon S3 where your query and calculation results are stored, such as 's3://path/to/query/bucket/'.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption
      description: If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey
      description: For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner
      description: The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption
      description: The Amazon S3 canned ACL that SecurityLake should specify when storing query results.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled
      description: True if previous query results can be reused when the query is run; otherwise, false. The default is false.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes
      description: Specifies, in minutes, the maximum age of a previous query result that SecurityLake should consider for reuse. The default is 60.
      type: Number
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Database
      description: The name of the database used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Catalog
      description: The name of the data catalog used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.State
      description: The state of the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.StateChangeReason
      description: Further detail about the status of the query.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.SubmissionDateTime
      description: The date and time that the query was submitted.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.CompletionDateTime
      description: The date and time that the query completed.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory
      description: An integer value that specifies the category of a query failure error.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorType
      description: An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.Retryable
      description: True if the query might succeed if resubmitted.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage
      description: Contains a short description of the error that occurred.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis
      description: The number of milliseconds that the query took to execute.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataScannedInBytes
      description: The number of bytes in the data that was queried.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataManifestLocation
      description: The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis
      description: The number of milliseconds that Athena took to run the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis
      description: The number of milliseconds that the query was in your query queue waiting for resources.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis
      description: The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis
      description: The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis
      description: The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult
      description: True if a previous query result was reused; false if the result was generated from a new run of the query.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.WorkGroup
      description: The name of the workgroup in which the query ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion
      description: The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion
      description: The engine version on which the query runs.
      type: String
    - contextPath: AWS.SecurityLake.Query.ExecutionParameters
      description: A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
      type: List
    - contextPath: AWS.SecurityLake.Query.SubstatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.MfaLoginQueryResults
      description: List of query results.
      type: List
  - name: aws-security-lake-source-ip-query
    description: Runs a query that takes a provided source IP address and queries the AWS Security Lake for console login attempts (Success/Failed) associated with the IP address, using AWS CloudTrail logs.
    deprecated: false
    arguments:
    - name: database
      description: The database to run the query against.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: table
      description: The table to run the query against.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: ip_src
      description: The source IP address to search for console login attempts.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: output_location
      description: The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
    - name: query_limit
      description: A limit (number) to use for the query. If the keyword 'LIMIT' exists within 'QueryString', this parameter will be ignored.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: QueryExecutionId
      hidden: true
      description: ID of the newly created query. Used internally for polling.
    - name: hide_polling_output
      hidden: true
      description: ""
    polling: true
    outputs:
    - contextPath: AWS.SecurityLake.Query.QueryExecutionId
      description: The unique identifier for each query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Query
      description: The SQL query statements which the query execution ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.StatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.OutputLocation
      description: The location in Amazon S3 where your query and calculation results are stored, such as 's3://path/to/query/bucket/'.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption
      description: If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey
      description: For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner
      description: The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption
      description: The Amazon S3 canned ACL that Athena should specify when storing query results.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled
      description: True if previous query results can be reused when the query is run; otherwise, false. The default is false.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes
      description: Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
      type: Number
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Database
      description: The name of the database used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Catalog
      description: The name of the data catalog used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.State
      description: The state of the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.StateChangeReason
      description: Further detail about the status of the query.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.SubmissionDateTime
      description: The date and time that the query was submitted.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.CompletionDateTime
      description: The date and time that the query completed.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory
      description: An integer value that specifies the category of a query failure error.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorType
      description: An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.Retryable
      description: True if the query might succeed if resubmitted.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage
      description: Contains a short description of the error that occurred.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis
      description: The number of milliseconds that the query took to execute.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataScannedInBytes
      description: The number of bytes in the data that was queried.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataManifestLocation
      description: The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis
      description: The number of milliseconds that Athena took to run the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis
      description: The number of milliseconds that the query was in your query queue waiting for resources.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis
      description: The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis
      description: The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis
      description: The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult
      description: True if a previous query result was reused; false if the result was generated from a new run of the query.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.WorkGroup
      description: The name of the workgroup in which the query ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion
      description: The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion
      description: The engine version on which the query runs.
      type: String
    - contextPath: AWS.SecurityLake.Query.ExecutionParameters
      description: A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
      type: List
    - contextPath: AWS.SecurityLake.Query.SubstatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.SourceIPQueryResults
      description: List of query results.
      type: List
  - name: aws-security-lake-guardduty-activity-query
    description: This command is used to search for Guard Duty logs for any criticality level activity.
    deprecated: false
    arguments:
    - name: database
      description: The database to run the query against.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: table
      description: The table to run the query against.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: severity
      description: The severity of related events to search for.
      required: true
      isArray: false
      defaultValue: ""
      auto: PREDEFINED
      predefined:
      - Unknown
      - Informational
      - Low
      - Medium
      - High
      - Critical
      - Fatal
      - Other
    - name: output_location
      description: The location in Amazon S3 where your query results are stored, such as s3://path/to/query/bucket/.
      required: true
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
    - name: query_limit
      description: A limit (number) to use for the query. If the keyword 'LIMIT' exists within 'QueryString', this parameter will be ignored.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: QueryExecutionId
      hidden: true
      description: ID of the newly created query. Used internally for polling.
    - name: hide_polling_output
      hidden: true
      description: ""
    polling: true
    outputs:
    - contextPath: AWS.SecurityLake.Query.QueryExecutionId
      description: The unique identifier for each query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Query
      description: The SQL query statements which the query execution ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.StatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.OutputLocation
      description: The location in Amazon S3 where your query and calculation results are stored, such as 's3://path/to/query/bucket/'.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.EncryptionOption
      description: If query and calculation results are encrypted in Amazon S3, indicates the encryption option used (for example, SSE_KMS or CSE_KMS) and key information.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.EncryptionConfiguration.KmsKey
      description: For SSE_KMS and CSE_KMS, this is the KMS key ARN or ID.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.ExpectedBucketOwner
      description: The Amazon Web Services account ID that you expect to be the owner of the Amazon S3 bucket specified by ResultConfiguration.OutputLocation.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultConfiguration.AclConfiguration.S3AclOption
      description: The Amazon S3 canned ACL that Athena should specify when storing query results.
      type: String
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.Enabled
      description: True if previous query results can be reused when the query is run; otherwise, false. The default is false.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.ResultReuseConfiguration.ResultReuseByAgeConfiguration.MaxAgeInMinutes
      description: Specifies, in minutes, the maximum age of a previous query result that Athena should consider for reuse. The default is 60.
      type: Number
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Database
      description: The name of the database used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.QueryExecutionContext.Catalog
      description: The name of the data catalog used in the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.State
      description: The state of the query execution.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.StateChangeReason
      description: Further detail about the status of the query.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.SubmissionDateTime
      description: The date and time that the query was submitted.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.CompletionDateTime
      description: The date and time that the query completed.
      type: String
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorCategory
      description: An integer value that specifies the category of a query failure error.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorType
      description: An integer value that provides specific information about an Athena query error. For the meaning of specific values, see the Error Type Reference in the Amazon Athena User Guide.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.Retryable
      description: True if the query might succeed if resubmitted.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.Status.AthenaError.ErrorMessage
      description: Contains a short description of the error that occurred.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.EngineExecutionTimeInMillis
      description: The number of milliseconds that the query took to execute.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataScannedInBytes
      description: The number of bytes in the data that was queried.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.DataManifestLocation
      description: The location and file name of a data manifest file. The manifest file is saved to the Athena query results location in Amazon S3.
      type: String
    - contextPath: AWS.SecurityLake.Query.Statistics.TotalExecutionTimeInMillis
      description: The number of milliseconds that Athena took to run the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryQueueTimeInMillis
      description: The number of milliseconds that the query was in your query queue waiting for resources.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServicePreProcessingTimeInMillis
      description: The number of milliseconds that Athena took to preprocess the query before submitting the query to the query engine.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.QueryPlanningTimeInMillis
      description: The number of milliseconds that Athena took to plan the query processing flow. This includes the time spent retrieving table partitions from the data source.
      type: Number
    - contextPath: AWS.SecurityLake.Query.Statistics.ServiceProcessingTimeInMillis
      description: The number of milliseconds that Athena took to finalize and publish the query results after the query engine finished running the query.
      type: Number
    - contextPath: AWS.SecurityLake.Query.ResultReuseInformation.ReusedPreviousResult
      description: True if a previous query result was reused; false if the result was generated from a new run of the query.
      type: Boolean
    - contextPath: AWS.SecurityLake.Query.WorkGroup
      description: The name of the workgroup in which the query ran.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.SelectedEngineVersion
      description: The engine version requested by the user. Possible values are determined by the output of ListEngineVersions, including AUTO.
      type: String
    - contextPath: AWS.SecurityLake.Query.EngineVersion.EffectiveEngineVersion
      description: The engine version on which the query runs.
      type: String
    - contextPath: AWS.SecurityLake.Query.ExecutionParameters
      description: A list of values for the parameters in a query. The values are applied sequentially to the parameters in the query in the order in which the parameters occur. The list of parameters is not returned in the response.
      type: List
    - contextPath: AWS.SecurityLake.Query.SubstatementType
      description: The type of query statement that was run.
      type: String
    - contextPath: AWS.SecurityLake.GuardDutyActivityQueryResults
      description: List of query results.
      type: List
  - name: aws-security-lake-data-sources-list
    description: Retrieves a snapshot of the current region, including whether Amazon Security Lake is enabled for those accounts and which sources Security Lake is collecting data from. In order to run this command the user must have 'securitylake' permissions.
    deprecated: false
    arguments:
    - name: accounts
      description: The Amazon Web Services account ID for which a static snapshot of the current Amazon Web Services Region, including enabled accounts and log sources, is retrieved.
      required: false
      isArray: true
      defaultValue: ""
      predefined:
      - ""
    - name: limit
      description: The maximum limit of accounts for which the static snapshot of the current region, including enabled accounts and log sources, is retrieved.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: next_token
      description: Lists if there are more results available. The value of nextToken is a unique pagination token for each page. Repeat the call using the returned token to retrieve the next page. Keep all other arguments unchanged.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
    - name: query_limit
      description: A limit (number) to use for the query. If the keyword 'LIMIT' exists within 'QueryString', this parameter will be ignored.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    outputs:
    - contextPath: AWS.SecurityLake.DataLakeSource.DataLakeArn
      description: The Amazon Resource Name (ARN) created by you to provide to the subscriber.
      type: String
    - contextPath: AWS.SecurityLake.DataLakeSource.DataLakeSources.account
      description: The ID of the Security Lake account for which logs are collected.
      type: String
    - contextPath: AWS.SecurityLake.DataLakeSource.DataLakeSources.eventClasses
      description: The Open Cybersecurity Schema Framework (OCSF) event classes which describes the type of data that the custom source will send to Security Lake.
      type: List
    - contextPath: AWS.SecurityLake.DataLakeSource.DataLakeSources.sourceName
      description: The supported Amazon Web Services from which logs and events are collected. Amazon Security Lake supports log and event collection for natively supported Amazon Web Services.
      type: String
    - contextPath: AWS.SecurityLake.DataLakeSource.DataLakeSources.sourceStatuses.resource
      description: Defines the path in which the stored logs are available which has information on your systems, applications, and services.
      type: String
    - contextPath: AWS.SecurityLake.DataLakeSource.DataLakeSources.sourceStatuses.status
      description: The health status of services, including error codes and patterns.
      type: String
    - contextPath: AWS.SecurityLake.DataLakeSourceNextToken
      description: Lists if there are more results available. The value of nextToken is a unique pagination token for each page. Repeat the call using the returned token to retrieve the next page. Keep all other arguments unchanged.
      type: String
  - name: aws-security-lake-data-lakes-list
    description: Retrieves the Amazon Security Lake configuration object for the specified Amazon Web Services Regions. In order to run this command the user must have 'securitylake' permissions.
    deprecated: false
    arguments:
    - name: regions
      description: The list of regions where Security Lake is enabled.
      required: false
      isArray: true
      defaultValue: ""
      predefined:
      - ""
    - name: roleArn
      description: The Amazon Resource Name (ARN) of the role to assume.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionName
      description: An identifier for the assumed role session.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: roleSessionDuration
      description: The duration, in seconds, of the role session. The value can range from 900 seconds (15 minutes) up to the maximum session duration setting for the role.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    - name: region
      description: The AWS region. If not specified, the default region will be used.
    - name: query_limit
      description: A limit (number) to use for the query. If the keyword 'LIMIT' exists within 'QueryString', this parameter will be ignored.
      required: false
      isArray: false
      defaultValue: ""
      predefined:
      - ""
    outputs:
    - contextPath: AWS.SecurityLake.createStatus
      description: Retrieves the status of the configuration operation for an account in Amazon Security Lake.
      type: String
    - contextPath: AWS.SecurityLake.dataLakeArn
      description: The Amazon Resource Name (ARN) created by you to provide to the subscriber.
      type: String
    - contextPath: AWS.SecurityLake.encryptionConfiguration.kmsKeyId
      description: The ID of the KMS encryption key used by Amazon Security Lake to encrypt the Security Lake object.
      type: String
    - contextPath: AWS.SecurityLake.lifecycleConfiguration.expiration.days
      description: Number of days before data expires in the Amazon Security Lake object.
      type: Number
    - contextPath: AWS.SecurityLake.lifecycleConfiguration.transitions.days
      description: Number of days before data transitions to a different S3 Storage Class in the Amazon Security Lake object.
      type: Number
    - contextPath: AWS.SecurityLake.lifecycleConfiguration.transitions.storageClass
      description: The range of storage classes that you can choose from based on the data access, resiliency, and cost requirements of your workloads.
      type: String
    - contextPath: AWS.SecurityLake.region
      description: The Amazon Web Services regions where Security Lake is enabled.
      type: String
    - contextPath: AWS.SecurityLake.replicationConfiguration.regions
      description: Replication enables automatic, asynchronous copying of objects across Amazon S3 buckets.
      type: String
    - contextPath: AWS.SecurityLake.replicationConfiguration.roleArn
      description: Replication settings for the Amazon S3 buckets. This parameter uses the Identity and Access Management (IAM) role you created that is managed by Security Lake, to ensure the replication setting is correct.
      type: String
    - contextPath: AWS.SecurityLake.s3BucketArn
      description: The ARN for the Amazon Security Lake Amazon S3 bucket.
      type: String
    - contextPath: AWS.SecurityLake.updateStatus.exception.code
      description: The reason code for the exception of the last UpdateDataLake or DeleteDataLake API request.
      type: String
    - contextPath: AWS.SecurityLake.updateStatus.exception.reason
      description: The reason for the exception of the last UpdateDataLake or DeleteDataLake API request.
      type: String
    - contextPath: AWS.SecurityLake.updateStatus.requestId
      description: The unique ID for the last UpdateDataLake or DeleteDataLake API request.
      type: String
    - contextPath: AWS.SecurityLake.updateStatus.status
      description: The status of the last UpdateDataLake or DeleteDataLake API request that was requested.
      type: String

  runonce: false
  script: "-"
  type: python
  subtype: python3
  dockerimage: demisto/boto3py3:1.0.0.10221838
  feed: false
  isfetch: false
fromversion: 6.10.0
tests:
- No tests (auto formatted)