Skip to content

GuardDuty  >  Operations  >  create_custom_detection_rule_association

create_custom_detection_rule_association

Operation

create_custom_detection_rule_association async

create_custom_detection_rule_association(input: CreateCustomDetectionRuleAssociationInput, plugins: list[Plugin] | None = None) -> CreateCustomDetectionRuleAssociationOutput

Enables a custom detection rule for your account by creating an association. You specify the rule and the mode in which it operates.

Parameters:

Name Type Description Default
input CreateCustomDetectionRuleAssociationInput

An instance of CreateCustomDetectionRuleAssociationInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
CreateCustomDetectionRuleAssociationOutput

An instance of CreateCustomDetectionRuleAssociationOutput.

Input

CreateCustomDetectionRuleAssociationInput dataclass

Dataclass for CreateCustomDetectionRuleAssociationInput structure.

Attributes

client_token class-attribute instance-attribute
client_token: str | None = None

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. Maximum 64 characters.

mode class-attribute instance-attribute
mode: str | None = None

The rule execution mode. Valid values: LIVE | DRY_RUN.

rule_id class-attribute instance-attribute
rule_id: str | None = None

The unique identifier for the custom detection rule.

tags class-attribute instance-attribute
tags: dict[str, str] | None = None

The tags to be added to the new custom detection rule association resource.

Output

CreateCustomDetectionRuleAssociationOutput dataclass

Dataclass for CreateCustomDetectionRuleAssociationOutput structure.

Attributes

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.

rule_association class-attribute instance-attribute
rule_association: AssociationDetail | None = None

The details of the newly created custom detection rule association.