import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS CloudWatch Observability Admin Telemetry Rule for an AWS Organization. * * An organization-wide telemetry rule defines how telemetry data (logs, metrics, or traces) should be collected for AWS resources across the accounts in your organization. The rule can target one or more Regions and configure a destination (such as CloudWatch Logs or S3) along with source-specific parameters for VPC flow logs, WAF logs, CloudTrail events, ELB access logs, and more. * * > **NOTE:** Before using this resource, telemetry evaluation for organization must be enabled. Use the `aws.observabilityadmin.TelemetryEvaluationForOrganization` resource to enable it. * * > **NOTE:** This resource can only be used from the organization management account. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluationForOrganization("example", {}); * const exampleTelemetryRuleForOrganization = new aws.observabilityadmin.TelemetryRuleForOrganization("example", { * rule: { * telemetryType: "Logs", * resourceType: "AWS::EC2::VPC", * }, * ruleName: "example-org-telemetry-rule", * }, { * dependsOn: [example], * }); * ``` * * ### VPC Flow Logs to CloudWatch Logs * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluationForOrganization("example", {}); * const exampleTelemetryRuleForOrganization = new aws.observabilityadmin.TelemetryRuleForOrganization("example", { * rule: { * destinationConfiguration: { * vpcFlowLogParameters: { * trafficType: "ALL", * maxAggregationInterval: 60, * }, * destinationType: "cloud-watch-logs", * destinationPattern: "/aws/vpcflowlogs/", * retentionInDays: 30, * }, * telemetryType: "Logs", * resourceType: "AWS::EC2::VPC", * telemetrySourceTypes: ["VPC_FLOW_LOGS"], * allRegions: true, * allowFieldUpdates: true, * }, * ruleName: "org-vpc-flow-logs-rule", * }, { * dependsOn: [example], * }); * ``` * * ### Scoped to Specific Organizational Units * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const current = aws.organizations.getOrganization({}); * const example = new aws.observabilityadmin.TelemetryEvaluationForOrganization("example", {}); * const exampleTelemetryRuleForOrganization = new aws.observabilityadmin.TelemetryRuleForOrganization("example", { * rule: { * telemetryType: "Logs", * resourceType: "AWS::EKS::Cluster", * scope: current.then(current => `OrganizationId = '${current.id}'`), * selectionCriteria: "ResourceTags.Environment = 'production'", * regions: [ * "us-east-1", * "us-west-2", * ], * }, * ruleName: "org-scoped-rule", * }, { * dependsOn: [example], * }); * ``` * * ### With Tags * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.observabilityadmin.TelemetryEvaluationForOrganization("example", {}); * const exampleTelemetryRuleForOrganization = new aws.observabilityadmin.TelemetryRuleForOrganization("example", { * rule: { * telemetryType: "Logs", * resourceType: "AWS::EC2::VPC", * }, * ruleName: "org-tagged-rule", * tags: { * Environment: "production", * Purpose: "organization-monitoring", * }, * }, { * dependsOn: [example], * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `ruleName` (String) Name of the telemetry rule. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import CloudWatch Observability Admin Telemetry Rules for Organization using `ruleName`. For example: * * ```sh * $ pulumi import aws:observabilityadmin/telemetryRuleForOrganization:TelemetryRuleForOrganization example example-org-telemetry-rule * ``` */ export declare class TelemetryRuleForOrganization extends pulumi.CustomResource { /** * Get an existing TelemetryRuleForOrganization resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: TelemetryRuleForOrganizationState, opts?: pulumi.CustomResourceOptions): TelemetryRuleForOrganization; /** * Returns true if the given object is an instance of TelemetryRuleForOrganization. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is TelemetryRuleForOrganization; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Configuration block for the organization telemetry rule. See `rule` below. */ readonly rule: pulumi.Output; /** * ARN of the organization telemetry rule. */ readonly ruleArn: pulumi.Output; /** * Name of the organization telemetry rule. Must be between 1 and 100 characters and contain only alphanumeric characters, hyphens, underscores, periods, hash symbols, and forward slashes. Changing this argument forces a new resource to be created. * * The following arguments are optional: */ readonly ruleName: pulumi.Output; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; readonly timeouts: pulumi.Output; /** * Create a TelemetryRuleForOrganization resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: TelemetryRuleForOrganizationArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering TelemetryRuleForOrganization resources. */ export interface TelemetryRuleForOrganizationState { /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration block for the organization telemetry rule. See `rule` below. */ rule?: pulumi.Input; /** * ARN of the organization telemetry rule. */ ruleArn?: pulumi.Input; /** * Name of the organization telemetry rule. Must be between 1 and 100 characters and contain only alphanumeric characters, hyphens, underscores, periods, hash symbols, and forward slashes. Changing this argument forces a new resource to be created. * * The following arguments are optional: */ ruleName?: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a TelemetryRuleForOrganization resource. */ export interface TelemetryRuleForOrganizationArgs { /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration block for the organization telemetry rule. See `rule` below. */ rule: pulumi.Input; /** * Name of the organization telemetry rule. Must be between 1 and 100 characters and contain only alphanumeric characters, hyphens, underscores, periods, hash symbols, and forward slashes. Changing this argument forces a new resource to be created. * * The following arguments are optional: */ ruleName: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } //# sourceMappingURL=telemetryRuleForOrganization.d.ts.map