Skip to content

GuardDuty  >  Operations  >  update_custom_detection_rule_org_configuration

update_custom_detection_rule_org_configuration

Operation

update_custom_detection_rule_org_configuration async

update_custom_detection_rule_org_configuration(input: UpdateCustomDetectionRuleOrgConfigurationInput, plugins: list[Plugin] | None = None) -> UpdateCustomDetectionRuleOrgConfigurationOutput

Updates the organization-level configuration for a custom detection rule, including the mode and include/exclude account lists.

Parameters:

Name Type Description Default
input UpdateCustomDetectionRuleOrgConfigurationInput

An instance of UpdateCustomDetectionRuleOrgConfigurationInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
UpdateCustomDetectionRuleOrgConfigurationOutput

An instance of UpdateCustomDetectionRuleOrgConfigurationOutput.

Input

UpdateCustomDetectionRuleOrgConfigurationInput dataclass

Dataclass for UpdateCustomDetectionRuleOrgConfigurationInput structure.

Attributes

exclude_account_ids class-attribute instance-attribute
exclude_account_ids: list[str] | None = None

The account IDs to exclude from the organization configuration. Mutually exclusive with IncludeAccountIds.

include_account_ids class-attribute instance-attribute
include_account_ids: list[str] | None = None

The account IDs to include in the organization configuration. Mutually exclusive with ExcludeAccountIds.

mode class-attribute instance-attribute
mode: str | None = None

The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

rule_id class-attribute instance-attribute
rule_id: str | None = None

The unique identifier for the custom detection rule.

Output

UpdateCustomDetectionRuleOrgConfigurationOutput dataclass

Dataclass for UpdateCustomDetectionRuleOrgConfigurationOutput structure.

Attributes

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.