Creates a new InsightFilters.
awsAccountIds AWS account ID that a finding is generated in. See String_Filter below for more details.
awsAccountNames The name of the AWS account in which a finding is generated. See String_Filter below for more details.
companyNames The name of the findings provider (company) that owns the solution (product) that generates findings. See String_Filter below for more details.
complianceAssociatedStandardsIds The unique identifier of a standard in which a control is enabled. See String_Filter below for more details.
complianceSecurityControlIds The unique identifier of a control across standards. See String_Filter below for more details.
complianceSecurityControlParametersNames The unique identifier of a control across standards. See String_Filter below for more details.
complianceSecurityControlParametersValues The current value of a security control parameter. See String_Filter below for more details.
complianceStatuses Exclusive to findings that are generated as the result of a check run against a specific rule in a supported standard, such as CIS AWS Foundations. Contains security standard-related finding details. See String Filter below for more details.
confidences A finding's confidence. Confidence is defined as the likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence is scored on a 0-100 basis using a ratio scale, where 0 means zero percent confidence and 100 means 100 percent confidence. See Number Filter below for more details.
createdAts An ISO8601-formatted timestamp that indicates when the security-findings provider captured the potential security issue that a finding captured. See Date Filter below for more details.
criticalities The level of importance assigned to the resources associated with the finding. A score of 0 means that the underlying resources have no criticality, and a score of 100 is reserved for the most critical resources. See Number Filter below for more details.
descriptions A finding's description. See String Filter below for more details.
findingProviderFieldsConfidences The finding provider value for the finding confidence. Confidence is defined as the likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence is scored on a 0-100 basis using a ratio scale, where 0 means zero percent confidence and 100 means 100 percent confidence. See Number Filter below for more details.
findingProviderFieldsCriticalities The finding provider value for the level of importance assigned to the resources associated with the findings. A score of 0 means that the underlying resources have no criticality, and a score of 100 is reserved for the most critical resources. See Number Filter below for more details.
findingProviderFieldsRelatedFindingsIds The finding identifier of a related finding that is identified by the finding provider. See String Filter below for more details.
findingProviderFieldsRelatedFindingsProductArns The ARN of the solution that generated a related finding that is identified by the finding provider. See String Filter below for more details.
findingProviderFieldsSeverityLabels The finding provider value for the severity label. See String Filter below for more details.
findingProviderFieldsSeverityOriginals The finding provider's original value for the severity. See String Filter below for more details.
findingProviderFieldsTypes One or more finding types that the finding provider assigned to the finding. Uses the format of namespace/category/classifier that classify a finding. Valid namespace values include: Software and Configuration Checks, TTPs, Effects, Unusual Behaviors, and Sensitive Data Identifications. See String Filter below for more details.
firstObservedAts An ISO8601-formatted timestamp that indicates when the security-findings provider first observed the potential security issue that a finding captured. See Date Filter below for more details.
generatorIds The identifier for the solution-specific component (a discrete unit of logic) that generated a finding. See String Filter below for more details.
ids The security findings provider-specific identifier for a finding. See String Filter below for more details.
keywords A keyword for a finding. See Keyword Filter below for more details.
lastObservedAts An ISO8601-formatted timestamp that indicates when the security-findings provider most recently observed the potential security issue that a finding captured. See Date Filter below for more details.
malwareNames The name of the malware that was observed. See String Filter below for more details.
malwarePaths The filesystem path of the malware that was observed. See String Filter below for more details.
malwareStates The state of the malware that was observed. See String Filter below for more details.
malwareTypes The type of the malware that was observed. See String Filter below for more details.
networkDestinationDomains The destination domain of network-related information about a finding. See String Filter below for more details.
networkDestinationIpv4s The destination IPv4 address of network-related information about a finding. See Ip Filter below for more details.
networkDestinationIpv6s The destination IPv6 address of network-related information about a finding. See Ip Filter below for more details.
networkDestinationPorts The destination port of network-related information about a finding. See Number Filter below for more details.
networkDirections Indicates the direction of network traffic associated with a finding. See String Filter below for more details.
networkProtocols The protocol of network-related information about a finding. See String Filter below for more details.
networkSourceDomains The source domain of network-related information about a finding. See String Filter below for more details.
networkSourceIpv4s The source IPv4 address of network-related information about a finding. See Ip Filter below for more details.
networkSourceIpv6s The source IPv6 address of network-related information about a finding. See Ip Filter below for more details.
networkSourceMacs The source media access control (MAC) address of network-related information about a finding. See String Filter below for more details.
networkSourcePorts The source port of network-related information about a finding. See Number Filter below for more details.
noteTexts The text of a note. See String Filter below for more details.
noteUpdatedAts The timestamp of when the note was updated. See Date Filter below for more details.
noteUpdatedBies The principal that created a note. See String Filter below for more details.
processLaunchedAts The date/time that the process was launched. See Date Filter below for more details.
processNames The name of the process. See String Filter below for more details.
processParentPids The parent process ID. See Number Filter below for more details.
processPaths The path to the process executable. See String Filter below for more details.
processPids The process ID. See Number Filter below for more details.
processTerminatedAts The date/time that the process was terminated. See Date Filter below for more details.
productArns The ARN generated by Security Hub that uniquely identifies a third-party company (security findings provider) after this provider's product (solution that generates findings) is registered with Security Hub. See String Filter below for more details.
productFields A data type where security-findings providers can include additional solution-specific details that aren't part of the defined AwsSecurityFinding format. See Map Filter below for more details.
productNames The name of the solution (product) that generates findings. See String Filter below for more details.
recommendationTexts The recommendation of what to do about the issue described in a finding. See String Filter below for more details.
recordStates The updated record state for the finding. See String Filter below for more details.
relatedFindingsIds The solution-generated identifier for a related finding. See String Filter below for more details.
relatedFindingsProductArns The ARN of the solution that generated a related finding. See String Filter below for more details.
resourceAwsEc2InstanceIamInstanceProfileArns The IAM profile ARN of the instance. See String Filter below for more details.
resourceAwsEc2InstanceImageIds AMI ID of the instance. See String Filter below for more details.
resourceAwsEc2InstanceIpv4Addresses The IPv4 addresses associated with the instance. See Ip Filter below for more details.
resourceAwsEc2InstanceIpv6Addresses The IPv6 addresses associated with the instance. See Ip Filter below for more details.
resourceAwsEc2InstanceKeyNames The key name associated with the instance. See String Filter below for more details.
resourceAwsEc2InstanceLaunchedAts The date and time the instance was launched. See Date Filter below for more details.
resourceAwsEc2InstanceSubnetIds The identifier of the subnet that the instance was launched in. See String Filter below for more details.
resourceAwsEc2InstanceTypes The instance type of the instance. See String Filter below for more details.
resourceAwsEc2InstanceVpcIds The identifier of the VPC that the instance was launched in. See String Filter below for more details.
resourceAwsIamAccessKeyCreatedAts The creation date/time of the IAM access key related to a finding. See Date Filter below for more details.
resourceAwsIamAccessKeyStatuses The status of the IAM access key related to a finding. See String Filter below for more details.
resourceAwsIamAccessKeyUserNames The user associated with the IAM access key related to a finding. See String Filter below for more details.
resourceAwsS3BucketOwnerIds The canonical user ID of the owner of the S3 bucket. See String Filter below for more details.
resourceAwsS3BucketOwnerNames The display name of the owner of the S3 bucket. See String Filter below for more details.
resourceContainerImageIds The identifier of the image related to a finding. See String Filter below for more details.
resourceContainerImageNames The name of the image related to a finding. See String Filter below for more details.
resourceContainerLaunchedAts The date/time that the container was started. See Date Filter below for more details.
resourceContainerNames The name of the container related to a finding. See String Filter below for more details.
resourceDetailsOthers The details of a resource that doesn't have a specific subfield for the resource type defined. See Map Filter below for more details.
resourceIds The canonical identifier for the given resource type. See String Filter below for more details.
resourcePartitions The canonical AWS partition name that the Region is assigned to. See String Filter below for more details.
resourceRegions The canonical AWS external Region name where this resource is located. See String Filter below for more details.
resourceTags A list of AWS tags associated with a resource at the time the finding was processed. See Map Filter below for more details.
resourceTypes Specifies the type of the resource that details are provided for. See String Filter below for more details.
severityLabels The label of a finding's severity. See String Filter below for more details.
sourceUrls A URL that links to a page about the current finding in the security-findings provider's solution. See String Filter below for more details.
threatIntelIndicatorCategories The category of a threat intelligence indicator. See String Filter below for more details.
threatIntelIndicatorLastObservedAts The date/time of the last observation of a threat intelligence indicator. See Date Filter below for more details.
threatIntelIndicatorSourceUrls The URL for more details from the source of the threat intelligence. See String Filter below for more details.
threatIntelIndicatorSources The source of the threat intelligence. See String Filter below for more details.
threatIntelIndicatorTypes The type of a threat intelligence indicator. See String Filter below for more details.
threatIntelIndicatorValues The value of a threat intelligence indicator. See String Filter below for more details.
titles A finding's title. See String Filter below for more details.
types A finding type in the format of namespace/category/classifier that classifies a finding. See String Filter below for more details.
updatedAts An ISO8601-formatted timestamp that indicates when the security-findings provider last updated the finding record. See Date Filter below for more details.
userDefinedValues A list of name/value string pairs associated with the finding. These are custom, user-defined fields added to a finding. See Map Filter below for more details.
verificationStates The veracity of a finding. See String Filter below for more details.
workflowStatuses The status of the investigation into a finding. See Workflow Status Filter below for more details.
Exclusive to findings that are generated as the result of a check run against a specific rule in a supported standard, such as CIS AWS Foundations. Contains security standard-related finding details. See String Filter below for more details.
A finding's confidence. Confidence is defined as the likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence is scored on a 0-100 basis using a ratio scale, where 0 means zero percent confidence and 100 means 100 percent confidence. See Number Filter below for more details.
An ISO8601-formatted timestamp that indicates when the security-findings provider captured the potential security issue that a finding captured. See Date Filter below for more details.
The level of importance assigned to the resources associated with the finding. A score of 0 means that the underlying resources have no criticality, and a score of 100 is reserved for the most critical resources. See Number Filter below for more details.
The finding provider value for the finding confidence. Confidence is defined as the likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence is scored on a 0-100 basis using a ratio scale, where 0 means zero percent confidence and 100 means 100 percent confidence. See Number Filter below for more details.
The finding provider value for the level of importance assigned to the resources associated with the findings. A score of 0 means that the underlying resources have no criticality, and a score of 100 is reserved for the most critical resources. See Number Filter below for more details.
One or more finding types that the finding provider assigned to the finding. Uses the format of namespace/category/classifier that classify a finding. Valid namespace values include: Software and Configuration Checks, TTPs, Effects, Unusual Behaviors, and Sensitive Data Identifications. See String Filter below for more details.
An ISO8601-formatted timestamp that indicates when the security-findings provider first observed the potential security issue that a finding captured. See Date Filter below for more details.
An ISO8601-formatted timestamp that indicates when the security-findings provider most recently observed the potential security issue that a finding captured. See Date Filter below for more details.
The ARN generated by Security Hub that uniquely identifies a third-party company (security findings provider) after this provider's product (solution that generates findings) is registered with Security Hub. See String Filter below for more details.
A data type where security-findings providers can include additional solution-specific details that aren't part of the defined AwsSecurityFinding format. See Map Filter below for more details.
An ISO8601-formatted timestamp that indicates when the security-findings provider last updated the finding record. See Date Filter below for more details.
A list of name/value string pairs associated with the finding. These are custom, user-defined fields added to a finding. See Map Filter below for more details.