turbot/aws_insights

Query: guardduty_detectors_for_cloudtrail_trail

Usage

powerpipe query aws_insights.query.guardduty_detectors_for_cloudtrail_trail

SQL

select
detector.arn as guardduty_detector_arn
from
aws_guardduty_detector as detector,
aws_cloudtrail_trail as t
where
t.account_id = detector.account_id
and t.region = detector.region
and detector.status = 'ENABLED'
and detector.data_sources is not null
and detector.data_sources -> 'CloudTrail' ->> 'Status' = 'ENABLED'
and t.arn = $1;