Security Incident Response

2026/10/08 - Security Incident Response - 1 new api methods

Changes  Adds support for retrieving finding-lifecycle metrics for an AWS Security Incident Response membership.

GetFindingMetrics (new) Link ΒΆ

Returns finding-lifecycle metrics for a membership over a date range.

See also: AWS API Documentation

Request Syntax

client.get_finding_metrics(
    membershipId='string',
    startDate=datetime(2015, 1, 1),
    endDate=datetime(2015, 1, 1)
)
type membershipId:

string

param membershipId:

[REQUIRED]

The membership ID to retrieve metrics for.

type startDate:

datetime

param startDate:

[REQUIRED]

The start of the day-aligned UTC window, inclusive.

type endDate:

datetime

param endDate:

[REQUIRED]

The end of the day-aligned UTC window, inclusive.

rtype:

dict

returns:

Response Syntax

{
    'findingsIngestedSecurityHub': 123,
    'findingsIngestedGuardDuty': 123,
    'findingsTriaged': 123,
    'findingsTriagedFalsePositive': 123,
    'findingsInvestigated': 123,
    'findingsInvestigatedFalsePositive': 123,
    'findingsEscalated': 123,
    'findingsEscalatedFalsePositive': 123,
    'findingsTruePositive': 123,
    'findingsInvestigatedInProgress': 123,
    'findingsEscalatedInProgress': 123
}

Response Structure

  • (dict) --

    Finding-lifecycle metrics for a membership over the requested date range.

    • findingsIngestedSecurityHub (integer) --

      The number of findings ingested from AWS Security Hub during the requested date range.

    • findingsIngestedGuardDuty (integer) --

      The number of findings ingested from Amazon GuardDuty during the requested date range.

    • findingsTriaged (integer) --

      The number of findings triaged during the requested date range.

    • findingsTriagedFalsePositive (integer) --

      The number of triaged findings that were closed as false positives during the requested date range.

    • findingsInvestigated (integer) --

      The number of findings investigated during the requested date range.

    • findingsInvestigatedFalsePositive (integer) --

      The number of investigated findings that were closed as false positives during the requested date range.

    • findingsEscalated (integer) --

      The number of findings escalated during the requested date range.

    • findingsEscalatedFalsePositive (integer) --

      The number of escalated findings that were closed as false positives during the requested date range.

    • findingsTruePositive (integer) --

      The number of findings confirmed as true positives during the requested date range.

    • findingsInvestigatedInProgress (integer) --

      The number of findings whose investigation was in progress during the requested date range.

    • findingsEscalatedInProgress (integer) --

      The number of findings whose escalation was in progress during the requested date range.