Skip to content

Create Threat Entity Set

guardduty_create_threat_entity_set R Documentation

Creates a new threat entity set

Description

Creates a new threat entity set. In a threat entity set, you can provide known malicious threat entities for your Amazon Web Services environment. GuardDuty generates findings based on the entries in the threat entity sets. Only users of the administrator account can manage entity sets, which automatically apply to member accounts.

Usage

guardduty_create_threat_entity_set(DetectorId, Name, Format, Location,
  ExpectedBucketOwner, Activate, ClientToken, Tags)

Arguments

DetectorId

[required] The unique ID of the detector of the GuardDuty account for which you want to create a threat entity set.

To find the detectorId in the current Region, see the Settings page in the GuardDuty console, or run the list_detectors API.

Name

[required] A user-friendly name to identify the threat entity set.

The name of your list can include lowercase letters, uppercase letters, numbers, dash (-), and underscore (_).

Format

[required] The format of the file that contains the threat entity set.

Location

[required] The URI of the file that contains the threat entity set. The format of the Location URL must be a valid Amazon S3 URL format. Invalid URL formats will result in an error, regardless of whether you activate the entity set or not. For more information about format of the location URLs, see Format of location URL under Step 2: Adding trusted or threat intelligence data in the Amazon GuardDuty User Guide.

ExpectedBucketOwner

The Amazon Web Services account ID that owns the Amazon S3 bucket specified in the location parameter.

Activate

[required] A boolean value that indicates whether GuardDuty should start using the uploaded threat entity set to generate findings.

ClientToken

The idempotency token for the create request.

Tags

The tags to be added to a new threat entity set resource.

Value

A list with the following syntax:

list(
  ThreatEntitySetId = "string"
)

Request syntax

svc$create_threat_entity_set(
  DetectorId = "string",
  Name = "string",
  Format = "TXT"|"STIX"|"OTX_CSV"|"ALIEN_VAULT"|"PROOF_POINT"|"FIRE_EYE",
  Location = "string",
  ExpectedBucketOwner = "string",
  Activate = TRUE|FALSE,
  ClientToken = "string",
  Tags = list(
    "string"
  )
)