create_threat_entity_set¶
Operation¶
create_threat_entity_set
async
¶
create_threat_entity_set(input: CreateThreatEntitySetInput, plugins: list[Plugin] | None = None) -> CreateThreatEntitySetOutput
Creates a new threat entity set. In a threat entity set, you can provide known malicious threat entities for your Amazon Web Services environment. GuardDuty generates findings based on the entries in the threat entity sets. Only users of the administrator account can manage entity sets, which automatically apply to member accounts.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
input
|
CreateThreatEntitySetInput
|
An instance of |
required |
plugins
|
list[Plugin] | None
|
A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations. |
None
|
Returns:
| Type | Description |
|---|---|
CreateThreatEntitySetOutput
|
An instance of |
Input¶
CreateThreatEntitySetInput
dataclass
¶
Dataclass for CreateThreatEntitySetInput structure.
Attributes¶
activate
class-attribute
instance-attribute
¶
activate: bool | None = None
A boolean value that indicates whether GuardDuty should start using the uploaded threat entity set to generate findings.
client_token
class-attribute
instance-attribute
¶
client_token: str | None = None
The idempotency token for the create request.
detector_id
class-attribute
instance-attribute
¶
detector_id: str | None = None
The unique ID of the detector of the GuardDuty account for which you want to create a threat entity set.
To find the detectorId in the current Region, see the Settings page in
the GuardDuty console, or run the
ListDetectors
API.
expected_bucket_owner
class-attribute
instance-attribute
¶
expected_bucket_owner: str | None = None
The Amazon Web Services account ID that owns the Amazon S3 bucket specified in the location parameter.
format
class-attribute
instance-attribute
¶
format: ThreatEntitySetFormat | None = None
The format of the file that contains the threat entity set.
location
class-attribute
instance-attribute
¶
location: str | None = None
The URI of the file that contains the threat entity set. The format of
the Location URL must be a valid Amazon S3 URL format. Invalid URL
formats will result in an error, regardless of whether you activate the
entity set or not. For more information about format of the location
URLs, see Format of location URL under Step 2: Adding trusted or threat
intelligence
data
in the Amazon GuardDuty User Guide.
name
class-attribute
instance-attribute
¶
name: str | None = None
A user-friendly name to identify the threat entity set.
The name of your list can include lowercase letters, uppercase letters, numbers, dash (-), and underscore (_).
tags
class-attribute
instance-attribute
¶
tags: dict[str, str] | None = None
The tags to be added to a new threat entity set resource.