Skip to content

GuardDuty  >  Structures  >  DetectionRuleOrgConfiguration

DetectionRuleOrgConfiguration

Structure Class

DetectionRuleOrgConfiguration dataclass

Contains the organization-level configuration for a custom detection rule.

Attributes

created_at class-attribute instance-attribute
created_at: datetime | None = None

The timestamp when the organization configuration was created.

exclude_account_ids class-attribute instance-attribute
exclude_account_ids: list[str] | None = None

A list of member account IDs excluded from the organization configuration. Mutually exclusive with IncludeAccountIds.

expires_at class-attribute instance-attribute
expires_at: datetime | None = None

The timestamp when the organization configuration expires.

include_account_ids class-attribute instance-attribute
include_account_ids: list[str] | None = None

A list of member account IDs included in the organization configuration. Mutually exclusive with ExcludeAccountIds.

mode class-attribute instance-attribute
mode: str | None = None

The execution mode of the organization configuration. Valid values: LIVE | DRY_RUN.

rule_id class-attribute instance-attribute
rule_id: str | None = None

The unique identifier for the custom detection rule.

status class-attribute instance-attribute
status: str | None = None

The configuration status. Valid values: ACTIVE | PROCESSING | FAILED.

status_reason class-attribute instance-attribute
status_reason: str | None = None

The reason for the current configuration status.

updated_at class-attribute instance-attribute
updated_at: datetime | None = None

The timestamp when the organization configuration was last updated.