GetCustomDetectionRule
Returns details for a custom detection rule in GuardDuty, including its detection logic.
Request Syntax
GET /custom-detection-rule/rule/RuleId HTTP/1.1
URI Request Parameters
The request uses the following URI parameters.
- RuleId
-
The unique identifier for the custom detection rule.
Length Constraints: Minimum length of 1. Maximum length of 100.
Pattern:
[a-z0-9]+(-[a-z0-9]+)*Required: Yes
Request Body
The request does not have a request body.
Response Syntax
HTTP/1.1 200
Content-type: application/json
{
"rule": {
"arn": "string",
"createdAt": number,
"dataSource": "string",
"definition": {
"expression": "string"
},
"description": "string",
"language": "string",
"name": "string",
"ruleId": "string",
"schema": "string",
"service": "string",
"severity": "string",
"tactic": "string",
"technique": "string",
"updatedAt": number
}
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- rule
-
The details of the custom detection rule.
Type: RuleDetail object
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
An access denied exception object.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 403
- BadRequestException
-
A bad request exception object.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 400
- InternalServerErrorException
-
An internal server error exception object.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 500
- ResourceNotFoundException
-
The requested resource can't be found.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 404
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: