[ aws . configservice ]
Returns configuration item that is aggregated for your specific resource in a specific source account and region.
See also: AWS API Documentation
See ‘aws help’ for descriptions of global parameters.
get-aggregate-resource-config
--configuration-aggregator-name <value>
--resource-identifier <value>
[--cli-input-json | --cli-input-yaml]
[--generate-cli-skeleton <value>]
--configuration-aggregator-name
(string)
The name of the configuration aggregator.
--resource-identifier
(structure)
An object that identifies aggregate resource.
SourceAccountId -> (string)
The 12-digit account ID of the source account.
SourceRegion -> (string)
The source region where data is aggregated.
ResourceId -> (string)
The ID of the AWS resource.
ResourceType -> (string)
The type of the AWS resource.
ResourceName -> (string)
The name of the AWS resource.
Shorthand Syntax:
SourceAccountId=string,SourceRegion=string,ResourceId=string,ResourceType=string,ResourceName=string
JSON Syntax:
{
"SourceAccountId": "string",
"SourceRegion": "string",
"ResourceId": "string",
"ResourceType": "AWS::EC2::CustomerGateway"|"AWS::EC2::EIP"|"AWS::EC2::Host"|"AWS::EC2::Instance"|"AWS::EC2::InternetGateway"|"AWS::EC2::NetworkAcl"|"AWS::EC2::NetworkInterface"|"AWS::EC2::RouteTable"|"AWS::EC2::SecurityGroup"|"AWS::EC2::Subnet"|"AWS::CloudTrail::Trail"|"AWS::EC2::Volume"|"AWS::EC2::VPC"|"AWS::EC2::VPNConnection"|"AWS::EC2::VPNGateway"|"AWS::EC2::RegisteredHAInstance"|"AWS::EC2::NatGateway"|"AWS::EC2::EgressOnlyInternetGateway"|"AWS::EC2::VPCEndpoint"|"AWS::EC2::VPCEndpointService"|"AWS::EC2::FlowLog"|"AWS::EC2::VPCPeeringConnection"|"AWS::Elasticsearch::Domain"|"AWS::IAM::Group"|"AWS::IAM::Policy"|"AWS::IAM::Role"|"AWS::IAM::User"|"AWS::ElasticLoadBalancingV2::LoadBalancer"|"AWS::ACM::Certificate"|"AWS::RDS::DBInstance"|"AWS::RDS::DBSubnetGroup"|"AWS::RDS::DBSecurityGroup"|"AWS::RDS::DBSnapshot"|"AWS::RDS::DBCluster"|"AWS::RDS::DBClusterSnapshot"|"AWS::RDS::EventSubscription"|"AWS::S3::Bucket"|"AWS::S3::AccountPublicAccessBlock"|"AWS::Redshift::Cluster"|"AWS::Redshift::ClusterSnapshot"|"AWS::Redshift::ClusterParameterGroup"|"AWS::Redshift::ClusterSecurityGroup"|"AWS::Redshift::ClusterSubnetGroup"|"AWS::Redshift::EventSubscription"|"AWS::SSM::ManagedInstanceInventory"|"AWS::CloudWatch::Alarm"|"AWS::CloudFormation::Stack"|"AWS::ElasticLoadBalancing::LoadBalancer"|"AWS::AutoScaling::AutoScalingGroup"|"AWS::AutoScaling::LaunchConfiguration"|"AWS::AutoScaling::ScalingPolicy"|"AWS::AutoScaling::ScheduledAction"|"AWS::DynamoDB::Table"|"AWS::CodeBuild::Project"|"AWS::WAF::RateBasedRule"|"AWS::WAF::Rule"|"AWS::WAF::RuleGroup"|"AWS::WAF::WebACL"|"AWS::WAFRegional::RateBasedRule"|"AWS::WAFRegional::Rule"|"AWS::WAFRegional::RuleGroup"|"AWS::WAFRegional::WebACL"|"AWS::CloudFront::Distribution"|"AWS::CloudFront::StreamingDistribution"|"AWS::Lambda::Function"|"AWS::NetworkFirewall::Firewall"|"AWS::NetworkFirewall::FirewallPolicy"|"AWS::NetworkFirewall::RuleGroup"|"AWS::ElasticBeanstalk::Application"|"AWS::ElasticBeanstalk::ApplicationVersion"|"AWS::ElasticBeanstalk::Environment"|"AWS::WAFv2::WebACL"|"AWS::WAFv2::RuleGroup"|"AWS::WAFv2::IPSet"|"AWS::WAFv2::RegexPatternSet"|"AWS::WAFv2::ManagedRuleSet"|"AWS::XRay::EncryptionConfig"|"AWS::SSM::AssociationCompliance"|"AWS::SSM::PatchCompliance"|"AWS::Shield::Protection"|"AWS::ShieldRegional::Protection"|"AWS::Config::ResourceCompliance"|"AWS::ApiGateway::Stage"|"AWS::ApiGateway::RestApi"|"AWS::ApiGatewayV2::Stage"|"AWS::ApiGatewayV2::Api"|"AWS::CodePipeline::Pipeline"|"AWS::ServiceCatalog::CloudFormationProvisionedProduct"|"AWS::ServiceCatalog::CloudFormationProduct"|"AWS::ServiceCatalog::Portfolio"|"AWS::SQS::Queue"|"AWS::KMS::Key"|"AWS::QLDB::Ledger"|"AWS::SecretsManager::Secret"|"AWS::SNS::Topic"|"AWS::SSM::FileData",
"ResourceName": "string"
}
--cli-input-json
| --cli-input-yaml
(string)
Reads arguments from the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton
. If other arguments are provided on the command line, those values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally. This may not be specified along with --cli-input-yaml
.
--generate-cli-skeleton
(string)
Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input
, prints a sample input JSON that can be used as an argument for --cli-input-json
. Similarly, if provided yaml-input
it will print a sample input YAML that can be used with --cli-input-yaml
. If provided with the value output
, it validates the command inputs and returns a sample output JSON for that command.
See ‘aws help’ for descriptions of global parameters.
ConfigurationItem -> (structure)
Returns a
ConfigurationItem
object.version -> (string)
The version number of the resource configuration.
accountId -> (string)
The 12-digit AWS account ID associated with the resource.
configurationItemCaptureTime -> (timestamp)
The time when the configuration recording was initiated.
configurationItemStatus -> (string)
The configuration item status. The valid values are:
OK – The resource configuration has been updated
ResourceDiscovered – The resource was newly discovered
ResourceNotRecorded – The resource was discovered but its configuration was not recorded since the recorder excludes the recording of resources of this type
ResourceDeleted – The resource was deleted
ResourceDeletedNotRecorded – The resource was deleted but its configuration was not recorded since the recorder excludes the recording of resources of this type
Note
The CIs do not incur any cost.
configurationStateId -> (string)
An identifier that indicates the ordering of the configuration items of a resource.
configurationItemMD5Hash -> (string)
Unique MD5 hash that represents the configuration item’s state.
You can use MD5 hash to compare the states of two or more configuration items that are associated with the same resource.
arn -> (string)
Amazon Resource Name (ARN) associated with the resource.
resourceType -> (string)
The type of AWS resource.
resourceId -> (string)
The ID of the resource (for example,
sg-xxxxxx
).resourceName -> (string)
The custom name of the resource, if available.
awsRegion -> (string)
The region where the resource resides.
availabilityZone -> (string)
The Availability Zone associated with the resource.
resourceCreationTime -> (timestamp)
The time stamp when the resource was created.
tags -> (map)
A mapping of key value tags associated with the resource.
key -> (string)
value -> (string)
relatedEvents -> (list)
A list of CloudTrail event IDs.
A populated field indicates that the current configuration was initiated by the events recorded in the CloudTrail log. For more information about CloudTrail, see What Is AWS CloudTrail .
An empty field indicates that the current configuration was not initiated by any event. As of Version 1.3, the relatedEvents field is empty. You can access the LookupEvents API in the AWS CloudTrail API Reference to retrieve the events for the resource.
(string)
relationships -> (list)
A list of related AWS resources.
(structure)
The relationship of the related resource to the main resource.
resourceType -> (string)
The resource type of the related resource.
resourceId -> (string)
The ID of the related resource (for example,
sg-xxxxxx
).resourceName -> (string)
The custom name of the related resource, if available.
relationshipName -> (string)
The type of relationship with the related resource.
configuration -> (string)
The description of the resource configuration.
supplementaryConfiguration -> (map)
Configuration attributes that AWS Config returns for certain resource types to supplement the information returned for the
configuration
parameter.key -> (string)
value -> (string)