Skip to content

Updates the organization-level configuration for a custom detection rule, including the mode and include/exclude account lists

Description

Updates the organization-level configuration for a custom detection rule, including the mode and include/exclude account lists.

Usage

guardduty_update_custom_detection_rule_org_configuration(RuleId, Mode,
  IncludeAccountIds, ExcludeAccountIds)

Arguments

  • RuleId

[required] The unique identifier for the custom detection rule.

  • Mode

[required] The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

  • IncludeAccountIds

The account IDs to include in the organization configuration. Mutually exclusive with ExcludeAccountIds.

  • ExcludeAccountIds

The account IDs to exclude from the organization configuration. Mutually exclusive with IncludeAccountIds.

Value

An empty list.

Request syntax

svc$update_custom_detection_rule_org_configuration(
  RuleId = "string",
  Mode = "LIVE"|"DRY_RUN",
  IncludeAccountIds = list(
    "string"
  ),
  ExcludeAccountIds = list(
    "string"
  )
)