Skip to content

Creates an organization-level configuration that enables a custom detection rule across your organization

Description

Creates an organization-level configuration that enables a custom detection rule across your organization. This operation is available only to the delegated administrator account.

Usage

guardduty_create_custom_detection_rule_org_configuration(RuleId, Mode,
  IncludeAccountIds, ExcludeAccountIds, ClientToken)

Arguments

  • RuleId

[required] The unique identifier for the custom detection rule.

  • Mode

[required] The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

  • IncludeAccountIds

The account IDs to include in the organization configuration. Mutually exclusive with ExcludeAccountIds.

  • ExcludeAccountIds

The account IDs to exclude from the organization configuration. Mutually exclusive with IncludeAccountIds.

  • ClientToken

A unique, case-sensitive identifier to ensure that the operation completes no more than one time.

Value

An empty list.

Request syntax

svc$create_custom_detection_rule_org_configuration(
  RuleId = "string",
  Mode = "LIVE"|"DRY_RUN",
  IncludeAccountIds = list(
    "string"
  ),
  ExcludeAccountIds = list(
    "string"
  ),
  ClientToken = "string"
)