

# GetThreatIntelSet


Retrieves the ThreatIntelSet that is specified by the ThreatIntelSet ID.

## Request Syntax


```
GET /detector/detectorId/threatintelset/threatIntelSetId HTTP/1.1
```

## URI Request Parameters


The request uses the following URI parameters.

 ** [detectorId](#API_GetThreatIntelSet_RequestSyntax) **   <a name="guardduty-GetThreatIntelSet-request-uri-DetectorId"></a>
The unique ID of the detector that is associated with the threatIntelSet.  
To find the `detectorId` in the current Region, see the Settings page in the GuardDuty console, or run the [ListDetectors](https://docs.aws.amazon.com/guardduty/latest/APIReference/API_ListDetectors.html) API.  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Required: Yes

 ** [threatIntelSetId](#API_GetThreatIntelSet_RequestSyntax) **   <a name="guardduty-GetThreatIntelSet-request-uri-ThreatIntelSetId"></a>
The unique ID of the threatIntelSet that you want to get.  
Required: Yes

## Request Body


The request does not have a request body.

## Response Syntax


```
HTTP/1.1 200
Content-type: application/json

{
   "expectedBucketOwner": "string",
   "format": "string",
   "location": "string",
   "name": "string",
   "status": "string",
   "tags": { 
      "string" : "string" 
   }
}
```

## Response Elements


If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

 ** [expectedBucketOwner](#API_GetThreatIntelSet_ResponseSyntax) **   <a name="guardduty-GetThreatIntelSet-response-expectedBucketOwner"></a>
The AWS account ID that owns the Amazon S3 bucket specified in the **location** parameter. This field appears in the response only if it was provided during ThreatIntelSet creation or update.  
Type: String  
Length Constraints: Fixed length of 12.

 ** [format](#API_GetThreatIntelSet_ResponseSyntax) **   <a name="guardduty-GetThreatIntelSet-response-format"></a>
The format of the threatIntelSet.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Valid Values: `TXT | STIX | OTX_CSV | ALIEN_VAULT | PROOF_POINT | FIRE_EYE` 

 ** [location](#API_GetThreatIntelSet_ResponseSyntax) **   <a name="guardduty-GetThreatIntelSet-response-location"></a>
The URI of the file that contains the ThreatIntelSet.   
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.

 ** [name](#API_GetThreatIntelSet_ResponseSyntax) **   <a name="guardduty-GetThreatIntelSet-response-name"></a>
A user-friendly ThreatIntelSet name displayed in all findings that are generated by activity that involves IP addresses included in this ThreatIntelSet.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.

 ** [status](#API_GetThreatIntelSet_ResponseSyntax) **   <a name="guardduty-GetThreatIntelSet-response-status"></a>
The status of threatIntelSet file uploaded.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Valid Values: `INACTIVE | ACTIVATING | ACTIVE | DEACTIVATING | ERROR | DELETE_PENDING | DELETED` 

 ** [tags](#API_GetThreatIntelSet_ResponseSyntax) **   <a name="guardduty-GetThreatIntelSet-response-tags"></a>
The tags of the threat list resource.  
Type: String to string map  
Map Entries: Maximum number of 200 items.  
Key Length Constraints: Minimum length of 1. Maximum length of 128.  
Key Pattern: `^(?!aws:)[a-zA-Z+-=._:/]+$`   
Value Length Constraints: Maximum length of 256.

## Errors


For information about the errors that are common to all actions, see [Common Error Types](CommonErrors.md).

 ** BadRequestException **   
A bad request exception object.    
 ** Message **   
The error message.  
 ** Type **   
The error type.
HTTP Status Code: 400

 ** InternalServerErrorException **   
An internal server error exception object.    
 ** Message **   
The error message.  
 ** Type **   
The error type.
HTTP Status Code: 500

## See Also


For more information about using this API in one of the language-specific AWS SDKs, see the following:
+  [AWS Command Line Interface V2](https://docs.aws.amazon.com/goto/cli2/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for .NET V4](https://docs.aws.amazon.com/goto/DotNetSDKV4/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for C\$1\$1](https://docs.aws.amazon.com/goto/SdkForCpp/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for Go v2](https://docs.aws.amazon.com/goto/SdkForGoV2/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for Java V2](https://docs.aws.amazon.com/goto/SdkForJavaV2/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for JavaScript V3](https://docs.aws.amazon.com/goto/SdkForJavaScriptV3/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for Kotlin](https://docs.aws.amazon.com/goto/SdkForKotlin/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for PHP V3](https://docs.aws.amazon.com/goto/SdkForPHPV3/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for Python](https://docs.aws.amazon.com/goto/boto3/guardduty-2017-11-28/GetThreatIntelSet) 
+  [AWS SDK for Ruby V3](https://docs.aws.amazon.com/goto/SdkForRubyV3/guardduty-2017-11-28/GetThreatIntelSet) 