startExportJobV2
Starts an ad hoc export job that writes Security Hub findings to an Amazon Simple Storage Service (Amazon S3) bucket that you own. Because the export runs asynchronously, this operation returns only the ExportJobId of the new job; it doesn't wait for the export to finish. Use GetExportJobV2 to poll the job, and ListExportJobsV2 to view the export jobs in your account.
Security Hub allows only one export job in the RUNNING state per account at a time. If an export job is already running, this operation returns a ServiceQuotaExceededException. Wait for the running job to finish, or cancel it with CancelExportJobV2, before you start a new one.
Specify the destination bucket and Amazon Web Services Key Management Service (Amazon Web Services KMS) key in the Destination parameter, and the output format (CSV or OCSF_JSON), optional filters, and field selection in the OutputConfiguration parameter. Before you call this operation, you must grant Security Hub permission to write to your bucket and use your Amazon Web Services KMS key by adding the bucket policy and key policy statements shown in the Examples section.
Two identities use your Amazon Web Services KMS key, and each needs its own permission. Security Hub uses the key when it writes the export objects to your bucket. The IAM principal that calls StartExportJobV2 must also have kms:GenerateDataKey and kms:Decrypt permissions on the key. The Examples section shows both grants.
A delegated administrator can use the optional Scopes parameter to export findings for specific organizations or organizational units (OUs).
To make the request idempotent, provide a ClientToken. If you retry a StartExportJobV2 request with the same ClientToken and the same request parameters, Security Hub returns the ExportJobId of the original job instead of starting a new one. If you reuse a ClientToken with different request parameters, this operation returns a ConflictException.
Samples
// The following example starts an export that writes selected fields of new, critical findings to an
// Amazon S3 bucket in CSV format.
val resp = securityHubClient.startExportJobV2 {
name = "quarterly-critical-findings"
destination = ExportDestination.S3(S3ExportDestination {
bucketArn = "arn:aws:s3:::amzn-s3-demo-bucket"
kmsKeyArn = "arn:aws:kms:aa-example-1:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
objectPrefix = "security-hub-exports/2026-Q1"
}
)
outputConfiguration = ExportOutput.Findings(FindingsOutput {
format = FindingsExportFormat.fromValue("CSV")
selectedFields = listOf<FindingsSelectableField>(
FindingsSelectableField.fromValue("finding_info.title"),
FindingsSelectableField.fromValue("severity"),
FindingsSelectableField.fromValue("status"),
FindingsSelectableField.fromValue("cloud.account.uid"),
FindingsSelectableField.fromValue("resources.uid")
)
filters = OcsfFindingFilters {
compositeOperator = AllowedOperators.fromValue("AND")
compositeFilters = listOf<CompositeFilter>(
CompositeFilter {
operator = AllowedOperators.fromValue("AND")
stringFilters = listOf<OcsfStringFilter>(
OcsfStringFilter {
fieldName = OcsfStringField.fromValue("severity")
filter = StringFilter {
value = "Critical"
comparison = StringFilterComparison.fromValue("EQUALS")
}
},
OcsfStringFilter {
fieldName = OcsfStringField.fromValue("status")
filter = StringFilter {
value = "New"
comparison = StringFilterComparison.fromValue("EQUALS")
}
}
)
}
)
}
}
)
clientToken = "b3d1f9a2-1c4e-4b9a-9f2e-EXAMPLE11111"
}// The following example, run by a delegated administrator, starts an export of the last 30 days of
// findings for a specific organizational unit (OU) in OCSF JSON format.
val resp = securityHubClient.startExportJobV2 {
destination = ExportDestination.S3(S3ExportDestination {
bucketArn = "arn:aws:s3:::amzn-s3-demo-bucket"
kmsKeyArn = "arn:aws:kms:aa-example-1:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}
)
outputConfiguration = ExportOutput.Findings(FindingsOutput {
format = FindingsExportFormat.fromValue("OCSF_JSON")
filters = OcsfFindingFilters {
compositeOperator = AllowedOperators.fromValue("AND")
compositeFilters = listOf<CompositeFilter>(
CompositeFilter {
operator = AllowedOperators.fromValue("AND")
dateFilters = listOf<OcsfDateFilter>(
OcsfDateFilter {
fieldName = OcsfDateField.fromValue("finding_info.last_seen_time_dt")
filter = DateFilter {
dateRange = DateRange {
value = 30
unit = DateRangeUnit.fromValue("DAYS")
comparison = DateRangeComparison.fromValue("WITHIN")
}
}
}
)
}
)
}
}
)
scopes = ExportScopes {
awsOrganizations = listOf<AwsOrganizationScope>(
AwsOrganizationScope {
organizationalUnitId = "ou-1234-a1b2c3d4"
}
)
}
}