S3ExportDestination
The Amazon S3 destination for an export, including the bucket, the Amazon Web Services KMS key used for encryption, and an optional object key prefix.
Types
Properties
The Amazon Resource Name (ARN) of the Amazon S3 bucket that Security Hub writes the export to. You must own the bucket, and its bucket policy must grant the Security Hub service principal (exportv2.securityhub.amazonaws.com) permission to write objects. For the required bucket policy, see the Examples section of StartExportJobV2.
The ARN of the Amazon Web Services KMS key that Security Hub uses to encrypt the export objects with server-side encryption. The key policy must allow the Security Hub service principal (exportv2.securityhub.amazonaws.com) to use the key through Amazon S3. For the required key policy, see the Examples section of StartExportJobV2.
An optional key prefix that Security Hub prepends to the Amazon S3 object keys of the export output. Use a prefix to organize exports within the bucket. The value can be up to 512 characters.