/AWS1/IF_SHB=>STARTEXPORTJOBV2()¶
About StartExportJobV2¶
Starts an ad hoc export job that writes Security Hub findings to an Amazon Simple Storage Service (Amazon S3) bucket that you own. Because the export runs asynchronously, this operation returns only the ExportJobId of the new job; it doesn't wait for the export to finish. Use GetExportJobV2 to poll the job, and ListExportJobsV2 to view the export jobs in your account.
Security Hub allows only one export job in the RUNNING state per account at a time. If an export job is already running, this operation returns a ServiceQuotaExceededException. Wait for the running job to finish, or cancel it with CancelExportJobV2, before you start a new one.
Specify the destination bucket and Amazon Web Services Key Management Service (Amazon Web Services KMS) key in the Destination parameter, and the output format (CSV or OCSF_JSON), optional filters, and field selection in the OutputConfiguration parameter. Before you call this operation, you must grant Security Hub permission to write to your bucket and use your Amazon Web Services KMS key by adding the bucket policy and key policy statements shown in the Examples section.
Two identities use your Amazon Web Services KMS key, and each needs its own permission. Security Hub uses the key when it writes the export objects to your bucket. The IAM principal that calls StartExportJobV2 must also have kms:GenerateDataKey and kms:Decrypt permissions on the key. The Examples section shows both grants.
A delegated administrator can use the optional Scopes parameter to export findings for specific organizations or organizational units (OUs).
To make the request idempotent, provide a ClientToken. If you retry a StartExportJobV2 request with the same ClientToken and the same request parameters, Security Hub returns the ExportJobId of the original job instead of starting a new one. If you reuse a ClientToken with different request parameters, this operation returns a ConflictException.
Method Signature¶
METHODS /AWS1/IF_SHB~STARTEXPORTJOBV2
IMPORTING
!IV_NAME TYPE /AWS1/SHBEXPORTNAME OPTIONAL
!IO_DESTINATION TYPE REF TO /AWS1/CL_SHBEXPORTDESTINATION OPTIONAL
!IO_OUTPUTCONFIGURATION TYPE REF TO /AWS1/CL_SHBEXPORTOUTPUT OPTIONAL
!IO_SCOPES TYPE REF TO /AWS1/CL_SHBEXPORTSCOPES OPTIONAL
!IV_CLIENTTOKEN TYPE /AWS1/SHBCLIENTTOKEN OPTIONAL
RETURNING
VALUE(OO_OUTPUT) TYPE REF TO /aws1/cl_shbstartexpjobv2rsp
RAISING
/AWS1/CX_SHBACCESSDENIEDEX
/AWS1/CX_SHBCONFLICTEXCEPTION
/AWS1/CX_SHBINTERNALSERVEREX
/AWS1/CX_SHBORGALUNITNOTFNDEX
/AWS1/CX_SHBORGNOTFOUNDEX
/AWS1/CX_SHBSERVICEQUOTAEXCDEX
/AWS1/CX_SHBTHROTTLINGEX
/AWS1/CX_SHBVALIDATIONEX
/AWS1/CX_SHBCLIENTEXC
/AWS1/CX_SHBSERVEREXC
/AWS1/CX_RT_TECHNICAL_GENERIC
/AWS1/CX_RT_SERVICE_GENERIC.
IMPORTING¶
Required arguments:¶
io_destination TYPE REF TO /AWS1/CL_SHBEXPORTDESTINATION /AWS1/CL_SHBEXPORTDESTINATION¶
The destination that Security Hub writes the export to. You must specify exactly one destination type. Currently, the only supported type is Amazon S3.
io_outputconfiguration TYPE REF TO /AWS1/CL_SHBEXPORTOUTPUT /AWS1/CL_SHBEXPORTOUTPUT¶
Specifies what data to export and how to format it. You must specify exactly one output type. Currently, the only supported type is
Findings.
Optional arguments:¶
iv_name TYPE /AWS1/SHBEXPORTNAME /AWS1/SHBEXPORTNAME¶
An optional, user-provided name for the export job that helps you identify it in
ListExportJobsV2results. The value can be 1–256 characters. Alphanumeric characters, spaces, and the following ASCII characters are permitted:. _ , : ( ) / + -.
io_scopes TYPE REF TO /AWS1/CL_SHBEXPORTSCOPES /AWS1/CL_SHBEXPORTSCOPES¶
Limits the export to findings from specific organizational units (OUs) or from the delegated administrator's organization. Only the delegated administrator account can use this parameter; other accounts that specify it receive an
AccessDeniedException.This parameter is optional. If you omit it, the delegated administrator exports findings from all accounts across the entire organization, and other accounts export only their own findings.
You can specify up to 10 entries in
Scopes.AwsOrganizations. If you specify multiple entries, Security Hub combines them using OR logic.
iv_clienttoken TYPE /AWS1/SHBCLIENTTOKEN /AWS1/SHBCLIENTTOKEN¶
A unique identifier used to ensure idempotency.
RETURNING¶
oo_output TYPE REF TO /aws1/cl_shbstartexpjobv2rsp /AWS1/CL_SHBSTARTEXPJOBV2RSP¶
Examples¶
Syntax Example¶
This is an example of the syntax for calling the method. It includes every possible argument and initializes every possible value. The data provided is not necessarily semantically accurate (for example the value "string" may be provided for something that is intended to be an instance ID, or in some cases two arguments may be mutually exclusive). The syntax shows the ABAP syntax for creating the various data structures.
DATA(lo_result) = lo_client->startexportjobv2(
io_destination = new /aws1/cl_shbexportdestination(
io_s3 = new /aws1/cl_shbs3exportdst(
iv_bucketarn = |string|
iv_kmskeyarn = |string|
iv_objectprefix = |string|
)
)
io_outputconfiguration = new /aws1/cl_shbexportoutput(
io_findings = new /aws1/cl_shbfindingsoutput(
io_filters = new /aws1/cl_shbocsffindingfilters(
it_compositefilters = VALUE /aws1/cl_shbcompositefilter=>tt_compositefilterlist(
(
new /aws1/cl_shbcompositefilter(
it_booleanfilters = VALUE /aws1/cl_shbocsfbooleanfilter=>tt_ocsfbooleanfilterlist(
(
new /aws1/cl_shbocsfbooleanfilter(
io_filter = new /aws1/cl_shbbooleanfilter( ABAP_TRUE )
iv_fieldname = |string|
)
)
)
it_datefilters = VALUE /aws1/cl_shbocsfdatefilter=>tt_ocsfdatefilterlist(
(
new /aws1/cl_shbocsfdatefilter(
io_filter = new /aws1/cl_shbdatefilter(
io_daterange = new /aws1/cl_shbdaterange(
iv_comparison = |string|
iv_unit = |string|
iv_value = 123
)
iv_end = |string|
iv_start = |string|
)
iv_fieldname = |string|
)
)
)
it_ipfilters = VALUE /aws1/cl_shbocsfipfilter=>tt_ocsfipfilterlist(
(
new /aws1/cl_shbocsfipfilter(
io_filter = new /aws1/cl_shbipfilter( |string| )
iv_fieldname = |string|
)
)
)
it_mapfilters = VALUE /aws1/cl_shbocsfmapfilter=>tt_ocsfmapfilterlist(
(
new /aws1/cl_shbocsfmapfilter(
io_filter = new /aws1/cl_shbmapfilter(
iv_comparison = |string|
iv_key = |string|
iv_value = |string|
)
iv_fieldname = |string|
)
)
)
it_nestedcompositefilters = VALUE /aws1/cl_shbcompositefilter=>tt_compositefilterlist(
)
it_numberfilters = VALUE /aws1/cl_shbocsfnumberfilter=>tt_ocsfnumberfilterlist(
(
new /aws1/cl_shbocsfnumberfilter(
io_filter = new /aws1/cl_shbnumberfilter(
iv_eq = '0.1'
iv_gt = '0.1'
iv_gte = '0.1'
iv_lt = '0.1'
iv_lte = '0.1'
)
iv_fieldname = |string|
)
)
)
it_stringfilters = VALUE /aws1/cl_shbocsfstringfilter=>tt_ocsfstringfilterlist(
(
new /aws1/cl_shbocsfstringfilter(
io_filter = new /aws1/cl_shbstringfilter(
iv_comparison = |string|
iv_value = |string|
)
iv_fieldname = |string|
)
)
)
iv_operator = |string|
)
)
)
iv_compositeoperator = |string|
)
it_selectedfields = VALUE /aws1/cl_shbfndgsselctfldlst_w=>tt_findingsselectedfieldlist(
( new /aws1/cl_shbfndgsselctfldlst_w( |string| ) )
)
iv_format = |string|
)
)
io_scopes = new /aws1/cl_shbexportscopes(
it_awsorganizations = VALUE /aws1/cl_shbawsorgscope=>tt_awsorganizationscopelist(
(
new /aws1/cl_shbawsorgscope(
iv_organizationalunitid = |string|
iv_organizationid = |string|
)
)
)
)
iv_clienttoken = |string|
iv_name = |string|
).
This is an example of reading all possible response values
lo_result = lo_result.
IF lo_result IS NOT INITIAL.
lv_exportjobid = lo_result->get_exportjobid( ).
ENDIF.
Example – Starting a CSV export of critical findings¶
The following example starts an export that writes selected fields of new, critical findings to an Amazon S3 bucket in CSV format.
DATA(lo_result) = lo_client->startexportjobv2(
io_destination = new /aws1/cl_shbexportdestination(
io_s3 = new /aws1/cl_shbs3exportdst(
iv_bucketarn = |arn:aws:s3:::amzn-s3-demo-bucket|
iv_kmskeyarn = |arn:aws:kms:aa-example-1:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab|
iv_objectprefix = |security-hub-exports/2026-Q1|
)
)
io_outputconfiguration = new /aws1/cl_shbexportoutput(
io_findings = new /aws1/cl_shbfindingsoutput(
io_filters = new /aws1/cl_shbocsffindingfilters(
it_compositefilters = VALUE /aws1/cl_shbcompositefilter=>tt_compositefilterlist(
(
new /aws1/cl_shbcompositefilter(
it_stringfilters = VALUE /aws1/cl_shbocsfstringfilter=>tt_ocsfstringfilterlist(
(
new /aws1/cl_shbocsfstringfilter(
io_filter = new /aws1/cl_shbstringfilter(
iv_comparison = |EQUALS|
iv_value = |Critical|
)
iv_fieldname = |severity|
)
)
(
new /aws1/cl_shbocsfstringfilter(
io_filter = new /aws1/cl_shbstringfilter(
iv_comparison = |EQUALS|
iv_value = |New|
)
iv_fieldname = |status|
)
)
)
iv_operator = |AND|
)
)
)
iv_compositeoperator = |AND|
)
it_selectedfields = VALUE /aws1/cl_shbfndgsselctfldlst_w=>tt_findingsselectedfieldlist(
( new /aws1/cl_shbfndgsselctfldlst_w( |finding_info.title| ) )
( new /aws1/cl_shbfndgsselctfldlst_w( |severity| ) )
( new /aws1/cl_shbfndgsselctfldlst_w( |status| ) )
( new /aws1/cl_shbfndgsselctfldlst_w( |cloud.account.uid| ) )
( new /aws1/cl_shbfndgsselctfldlst_w( |resources.uid| ) )
)
iv_format = |CSV|
)
)
iv_clienttoken = |b3d1f9a2-1c4e-4b9a-9f2e-EXAMPLE11111|
iv_name = |quarterly-critical-findings|
).
Example – Starting an OCSF JSON export scoped to an organizational unit¶
The following example, run by a delegated administrator, starts an export of the last 30 days of findings for a specific organizational unit (OU) in OCSF JSON format.
DATA(lo_result) = lo_client->startexportjobv2(
io_destination = new /aws1/cl_shbexportdestination(
io_s3 = new /aws1/cl_shbs3exportdst(
iv_bucketarn = |arn:aws:s3:::amzn-s3-demo-bucket|
iv_kmskeyarn = |arn:aws:kms:aa-example-1:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab|
)
)
io_outputconfiguration = new /aws1/cl_shbexportoutput(
io_findings = new /aws1/cl_shbfindingsoutput(
io_filters = new /aws1/cl_shbocsffindingfilters(
it_compositefilters = VALUE /aws1/cl_shbcompositefilter=>tt_compositefilterlist(
(
new /aws1/cl_shbcompositefilter(
it_datefilters = VALUE /aws1/cl_shbocsfdatefilter=>tt_ocsfdatefilterlist(
(
new /aws1/cl_shbocsfdatefilter(
io_filter = new /aws1/cl_shbdatefilter(
io_daterange = new /aws1/cl_shbdaterange(
iv_comparison = |WITHIN|
iv_unit = |DAYS|
iv_value = 30
)
)
iv_fieldname = |finding_info.last_seen_time_dt|
)
)
)
iv_operator = |AND|
)
)
)
iv_compositeoperator = |AND|
)
iv_format = |OCSF_JSON|
)
)
io_scopes = new /aws1/cl_shbexportscopes(
it_awsorganizations = VALUE /aws1/cl_shbawsorgscope=>tt_awsorganizationscopelist(
( new /aws1/cl_shbawsorgscope( iv_organizationalunitid = |ou-1234-a1b2c3d4| ) )
)
)
).