Skip to content

This API is currently available as a preview

Description

This API is currently available as a preview. This feature is available in the following Amazon Web Services Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).

Retrieves the results and status of a specific GuardDuty investigation.

An administrator account can retrieve any investigation within the organization. Member accounts can only retrieve investigations that belong to them.

Usage

guardduty_get_investigation(DetectorId, InvestigationId)

Arguments

  • DetectorId

[required] The unique ID of the GuardDuty detector associated with the investigation.

To find the detectorId in the current Region, see the Settings page in the GuardDuty console, or run the list_detectors API.

  • InvestigationId

[required] The unique identifier of the investigation to retrieve.

Value

A list with the following syntax:

list(
  Investigation = list(
    InvestigationId = "string",
    Status = "RUNNING"|"COMPLETED"|"FAILED",
    TriggerPrompt = "string",
    TriggeredBy = "string",
    Metadata = list(
      Version = "string",
      Product = list(
        Name = "string",
        Feature = "string"
      )
    ),
    Cloud = list(
      Provider = "AWS",
      Region = "string",
      Account = "string"
    ),
    RiskLevel = "Info"|"Low"|"Medium"|"High"|"Critical",
    Risk = "string",
    Confidence = "Unknown"|"Low"|"Medium"|"High",
    Summary = "string",
    StartTime = as.POSIXct(
      "2015-01-01"
    ),
    EndTime = as.POSIXct(
      "2015-01-01"
    ),
    Error = "string"
  )
)

Request syntax

svc$get_investigation(
  DetectorId = "string",
  InvestigationId = "string"
)