The following arguments are supported:
The datasources block supports the following:
The s3_logs block supports the following:
The kubernetes block supports the following:
The audit_logs block supports the following:
malware_protection block supports the following:
The scan_ec2_instance_with_findings block supports the following:
The ebs_volumes block supports the following:
resource "aws_guardduty_detector" "MyDetector" {
enable = true
datasources {
s3_logs {
enable = true
}
kubernetes {
audit_logs {
enable = false
}
}
malware_protection {
scan_ec2_instance_with_findings {
ebs_volumes {
enable = true
}
}
}
}
}
create-detector
--enable | --no-enable
[--client-token <value>]
[--finding-publishing-frequency <value>]
[--data-sources <value>]
[--tags <value>]
[--cli-input-json | --cli-input-yaml]
[--generate-cli-skeleton <value>]
[--debug]
[--endpoint-url <value>]
[--no-verify-ssl]
[--no-paginate]
[--output <value>]
[--query <value>]
[--profile <value>]
[--region <value>]
[--version <value>]
[--color <value>]
[--no-sign-request]
[--ca-bundle <value>]
[--cli-read-timeout <value>]
[--cli-connect-timeout <value>]
[--cli-binary-format <value>]
[--no-cli-pager]
[--cli-auto-prompt]
[--no-cli-auto-prompt]
aws guardduty create-detector \
--enable
per Events for PaidS3DataEventsAnalyzed in a region
per GB for the first 500 GB / month of data analyzed in a region
per CloudTrail event analyzed in a region
per S3 Data Event for the first 500000000 events / month analyzed in a region
Categorized by Availability, Security & Compliance and Cost