Class: Aws::SecurityHub::Types::S3ExportDestination
- Inherits:
-
Struct
- Object
- Struct
- Aws::SecurityHub::Types::S3ExportDestination
- Defined in:
- gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb
Overview
The Amazon S3 destination for an export, including the bucket, the Amazon Web Services KMS key used for encryption, and an optional object key prefix.
Constant Summary collapse
- SENSITIVE =
[]
Instance Attribute Summary collapse
-
#bucket_arn ⇒ String
The Amazon Resource Name (ARN) of the Amazon S3 bucket that Security Hub writes the export to.
-
#kms_key_arn ⇒ String
The ARN of the Amazon Web Services KMS key that Security Hub uses to encrypt the export objects with server-side encryption.
-
#object_prefix ⇒ String
An optional key prefix that Security Hub prepends to the Amazon S3 object keys of the export output.
Instance Attribute Details
#bucket_arn ⇒ String
The Amazon Resource Name (ARN) of the Amazon S3 bucket that Security
Hub writes the export to. You must own the bucket, and its bucket
policy must grant the Security Hub service principal
(exportv2.securityhub.amazonaws.com) permission to write objects.
For the required bucket policy, see the Examples section of
StartExportJobV2.
33694 33695 33696 33697 33698 33699 33700 |
# File 'gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb', line 33694 class S3ExportDestination < Struct.new( :bucket_arn, :kms_key_arn, :object_prefix) SENSITIVE = [] include Aws::Structure end |
#kms_key_arn ⇒ String
The ARN of the Amazon Web Services KMS key that Security Hub uses to
encrypt the export objects with server-side encryption. The key
policy must allow the Security Hub service principal
(exportv2.securityhub.amazonaws.com) to use the key through Amazon
S3. For the required key policy, see the Examples section of
StartExportJobV2.
The key must meet all of the following requirements:
It must be a symmetric key with a key usage of
ENCRYPT_DECRYPT.It must be a single-Region key. Multi-Region keys, whose key IDs begin with
mrk-, are rejected.You must specify the full key ARN. Key IDs and aliases are rejected.
The key must be in the same Amazon Web Services account as the export job.
The key must be in the same Amazon Web Services Region as the export job.
The key must be in the
aws,aws-cn, oraws-us-govpartition.
33694 33695 33696 33697 33698 33699 33700 |
# File 'gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb', line 33694 class S3ExportDestination < Struct.new( :bucket_arn, :kms_key_arn, :object_prefix) SENSITIVE = [] include Aws::Structure end |
#object_prefix ⇒ String
An optional key prefix that Security Hub prepends to the Amazon S3 object keys of the export output. Use a prefix to organize exports within the bucket. The value can be up to 512 characters.
33694 33695 33696 33697 33698 33699 33700 |
# File 'gems/aws-sdk-securityhub/lib/aws-sdk-securityhub/types.rb', line 33694 class S3ExportDestination < Struct.new( :bucket_arn, :kms_key_arn, :object_prefix) SENSITIVE = [] include Aws::Structure end |