import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages a Security Hub V2 Automation Rule, which automatically updates or takes action on findings that match specified criteria. * * > **NOTE:** Automation rules must be created in the aggregation (home) region. A Security Hub V2 Aggregator (`aws.securityhub.AggregatorV2`) must exist before creating automation rules. * * ## Example Usage * * ### Basic * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.securityhub.AccountV2("example", {}); * const exampleAggregatorV2 = new aws.securityhub.AggregatorV2("example", {regionLinkingMode: "ALL_REGIONS"}, { * dependsOn: [example], * }); * const exampleAutomationRuleV2 = new aws.securityhub.AutomationRuleV2("example", { * criteria: { * ocsfFindingCriteriaJson: JSON.stringify({ * CompositeFilters: [{ * StringFilters: [{ * FieldName: "metadata.product.name", * Filter: { * Comparison: "EQUALS", * Value: "GuardDuty", * }, * }], * }], * CompositeOperator: "AND", * }), * }, * action: { * findingFieldsUpdate: { * severityId: 99, * statusId: 3, * comment: "Low severity GuardDuty finding suppressed", * }, * type: "FINDING_FIELDS_UPDATE", * }, * ruleName: "suppress-guardduty-low", * description: "Suppress low severity GuardDuty findings", * ruleOrder: 100, * ruleStatus: "ENABLED", * }, { * dependsOn: [exampleAggregatorV2], * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `arn` (String) ARN of the Security Hub V2 automation rule. * * Using `pulumi import`, import Security Hub V2 automation rules using `arn`. For example: * * ```sh * $ pulumi import aws:securityhub/automationRuleV2:AutomationRuleV2 example arn:aws:securityhub:us-east-1:123456789012:automation-rulev2/3efb04f4-e19e-4458-a698-62364ab7b1a7 * ``` */ export declare class AutomationRuleV2 extends pulumi.CustomResource { /** * Get an existing AutomationRuleV2 resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: AutomationRuleV2State, opts?: pulumi.CustomResourceOptions): AutomationRuleV2; /** * Returns true if the given object is an instance of AutomationRuleV2. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is AutomationRuleV2; /** * Actions to take when the rule matches. Maximum of 1 action block. See `action` below. */ readonly action: pulumi.Output; readonly arn: pulumi.Output; /** * Filtering type and configuration of the automation rule. See `criteria` below. */ readonly criteria: pulumi.Output; /** * A description of the automation rule. */ readonly description: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * ID of the automation rule. */ readonly ruleId: pulumi.Output; /** * The name of the automation rule. */ readonly ruleName: pulumi.Output; /** * The priority of the rule. Lower values indicate higher priority. */ readonly ruleOrder: pulumi.Output; /** * The status of the rule. Valid values: `ENABLED`, `DISABLED`. Defaults to `ENABLED`. */ readonly ruleStatus: pulumi.Output; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; /** * Create a AutomationRuleV2 resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: AutomationRuleV2Args, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering AutomationRuleV2 resources. */ export interface AutomationRuleV2State { /** * Actions to take when the rule matches. Maximum of 1 action block. See `action` below. */ action?: pulumi.Input; arn?: pulumi.Input; /** * Filtering type and configuration of the automation rule. See `criteria` below. */ criteria?: pulumi.Input; /** * A description of the automation rule. */ description?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ID of the automation rule. */ ruleId?: pulumi.Input; /** * The name of the automation rule. */ ruleName?: pulumi.Input; /** * The priority of the rule. Lower values indicate higher priority. */ ruleOrder?: pulumi.Input; /** * The status of the rule. Valid values: `ENABLED`, `DISABLED`. Defaults to `ENABLED`. */ ruleStatus?: pulumi.Input; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; } /** * The set of arguments for constructing a AutomationRuleV2 resource. */ export interface AutomationRuleV2Args { /** * Actions to take when the rule matches. Maximum of 1 action block. See `action` below. */ action: pulumi.Input; /** * Filtering type and configuration of the automation rule. See `criteria` below. */ criteria: pulumi.Input; /** * A description of the automation rule. */ description: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * The name of the automation rule. */ ruleName: pulumi.Input; /** * The priority of the rule. Lower values indicate higher priority. */ ruleOrder: pulumi.Input; /** * The status of the rule. Valid values: `ENABLED`, `DISABLED`. Defaults to `ENABLED`. */ ruleStatus?: pulumi.Input; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; } //# sourceMappingURL=automationRuleV2.d.ts.map