aws.insight-rule
Filters
Actions
delete
Delete a cloudwatch contributor insight rule
- example:
policies:
- name: cloudwatch-delete-insight-rule
resource: insight-rule
filters:
- type: value
key: State
value: ENABLED
op: eq
actions:
- delete
properties:
type:
enum:
- delete
required:
- type
Permissions - cloudwatch:DeleteInsightRules
disable
Disable a cloudwatch contributor insight rule.
- example:
policies:
- name: cloudwatch-disable-insight-rule
resource: insight-rule
filters:
- type: value
key: State
value: ENABLED
op: eq
actions:
- disable
properties:
type:
enum:
- disable
required:
- type
Permissions - cloudwatch:DisableInsightRules
rename-tag
Rename an existing tag key to a new value.
- example:
rename Application, and Bap to App, if a resource has both of the old keys then we’ll use the value specified by Application, which is based on the order of values of old_keys.
policies: - name: rename-tags-example resource: aws.log-group filters: - or: - "tag:Bap": present - "tag:Application": present actions: - type: rename-tag old_keys: [Application, Bap] new_key: App
properties:
new_key:
type: string
old_key:
type: string
old_keys:
items:
type: string
type: array
type:
enum:
- rename-tag
required:
- type
Permissions - tag:TagResources, tag:UntagResources