Skip to content

GuardDuty  >  Operations  >  list_custom_detection_rules

list_custom_detection_rules

Operation

list_custom_detection_rules async

list_custom_detection_rules(input: ListCustomDetectionRulesInput, plugins: list[Plugin] | None = None) -> ListCustomDetectionRulesOutput

Returns all available custom detection rules in GuardDuty. You can filter the results by data source, severity, tactic, technique, and service.

Parameters:

Name Type Description Default
input ListCustomDetectionRulesInput

An instance of ListCustomDetectionRulesInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
ListCustomDetectionRulesOutput

An instance of ListCustomDetectionRulesOutput.

Input

ListCustomDetectionRulesInput dataclass

Dataclass for ListCustomDetectionRulesInput structure.

Attributes

filters class-attribute instance-attribute
filters: list[DetectionRuleFilter] | None = None

A list of filter criteria to apply when listing custom detection rules.

max_results class-attribute instance-attribute
max_results: int | None = None

The maximum number of results to return in a single page. Minimum value of 1, maximum value of 100.

next_token class-attribute instance-attribute
next_token: str | None = None

A pagination token from a previous response. Use this token to retrieve the next page of results.

Output

ListCustomDetectionRulesOutput dataclass

Dataclass for ListCustomDetectionRulesOutput structure.

Attributes

next_token class-attribute instance-attribute
next_token: str | None = None

A pagination token to retrieve the next page of results. If this field is empty, there are no additional results.

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.

rules class-attribute instance-attribute
rules: list[RuleSummary] | None = None

A list of custom detection rule summaries.