Skip to content

GuardDuty  >  Operations  >  create_custom_detection_rule_org_configuration

create_custom_detection_rule_org_configuration

Operation

create_custom_detection_rule_org_configuration async

create_custom_detection_rule_org_configuration(input: CreateCustomDetectionRuleOrgConfigurationInput, plugins: list[Plugin] | None = None) -> CreateCustomDetectionRuleOrgConfigurationOutput

Creates an organization-level configuration that enables a custom detection rule across your organization. This operation is available only to the delegated administrator account.

Parameters:

Name Type Description Default
input CreateCustomDetectionRuleOrgConfigurationInput

An instance of CreateCustomDetectionRuleOrgConfigurationInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
CreateCustomDetectionRuleOrgConfigurationOutput

An instance of CreateCustomDetectionRuleOrgConfigurationOutput.

Input

CreateCustomDetectionRuleOrgConfigurationInput dataclass

Dataclass for CreateCustomDetectionRuleOrgConfigurationInput structure.

Attributes

client_token class-attribute instance-attribute
client_token: str | None = None

A unique, case-sensitive identifier to ensure that the operation completes no more than one time.

exclude_account_ids class-attribute instance-attribute
exclude_account_ids: list[str] | None = None

The account IDs to exclude from the organization configuration. Mutually exclusive with IncludeAccountIds.

include_account_ids class-attribute instance-attribute
include_account_ids: list[str] | None = None

The account IDs to include in the organization configuration. Mutually exclusive with ExcludeAccountIds.

mode class-attribute instance-attribute
mode: str | None = None

The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

rule_id class-attribute instance-attribute
rule_id: str | None = None

The unique identifier for the custom detection rule.

Output

CreateCustomDetectionRuleOrgConfigurationOutput dataclass

Dataclass for CreateCustomDetectionRuleOrgConfigurationOutput structure.

Attributes

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.