Class: Aws::SecurityHub::Types::S3ExportDestination

Inherits:
Struct
  • Object
show all
Defined in:
gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb

Overview

The Amazon S3 destination for an export, including the bucket, the Amazon Web Services KMS key used for encryption, and an optional object key prefix.

Constant Summary collapse

SENSITIVE =
[]

Instance Attribute Summary collapse

Instance Attribute Details

#bucket_arn ⇒ String

The Amazon Resource Name (ARN) of the Amazon S3 bucket that Security Hub writes the export to. You must own the bucket, and its bucket policy must grant the Security Hub service principal (exportv2.securityhub.amazonaws.com) permission to write objects. For the required bucket policy, see the Examples section of StartExportJobV2.

Returns:

  • (String)


33694
33695
33696
33697
33698
33699
33700
# File 'gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb', line 33694

class S3ExportDestination < Struct.new(
  :bucket_arn,
  :kms_key_arn,
  :object_prefix)
  SENSITIVE = []
  include Aws::Structure
end

#kms_key_arn ⇒ String

The ARN of the Amazon Web Services KMS key that Security Hub uses to encrypt the export objects with server-side encryption. The key policy must allow the Security Hub service principal (exportv2.securityhub.amazonaws.com) to use the key through Amazon S3. For the required key policy, see the Examples section of StartExportJobV2.

The key must meet all of the following requirements:

  • It must be a symmetric key with a key usage of ENCRYPT_DECRYPT.

  • It must be a single-Region key. Multi-Region keys, whose key IDs begin with mrk-, are rejected.

  • You must specify the full key ARN. Key IDs and aliases are rejected.

  • The key must be in the same Amazon Web Services account as the export job.

  • The key must be in the same Amazon Web Services Region as the export job.

  • The key must be in the aws, aws-cn, or aws-us-gov partition.

Returns:

  • (String)


33694
33695
33696
33697
33698
33699
33700
# File 'gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb', line 33694

class S3ExportDestination < Struct.new(
  :bucket_arn,
  :kms_key_arn,
  :object_prefix)
  SENSITIVE = []
  include Aws::Structure
end

#object_prefix ⇒ String

An optional key prefix that Security Hub prepends to the Amazon S3 object keys of the export output. Use a prefix to organize exports within the bucket. The value can be up to 512 characters.

Returns:

  • (String)


33694
33695
33696
33697
33698
33699
33700
# File 'gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb', line 33694

class S3ExportDestination < Struct.new(
  :bucket_arn,
  :kms_key_arn,
  :object_prefix)
  SENSITIVE = []
  include Aws::Structure
end