Policy: AWS > Turbot > Event Handlers > Events > Rules > Custom Event Patterns > @turbot/aws-ec2 > Excluded Roles
A list of IAM role names whose CloudTrail events will be excluded from the aws.ec2 EventBridge rule generated for this account/region by the AWS > Turbot > Event Handlers stack.
Each role name is matched against detail.userIdentity.sessionContext.sessionIssuer.userName in the event. Events from IAM users and the account root (which have no session issuer) are unaffected, as are events from any role not in this list.
Use this to suppress high-volume, low-value events generated by AWS-managed replication roles - for example the AWS Elastic Disaster Recovery (DRS) and AWS Application Migration Service (MGN) replication roles, which continuously create and delete EBS snapshots that have no compliance value in Guardrails.
Example: - AWSElasticDisasterRecoveryReplicationServerRole - AWSServiceRoleForElasticDisasterRecovery - AWSApplicationMigrationReplicationServerRole
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Policy Specification
Schema Type | |
|---|---|
Default | |
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/configured
- tmod:@turbot/aws-ec2#/policy/types/ec2CustomEventPatternsExcludedRoles
- turbot graphql policy-type --id "tmod:@turbot/aws-ec2#/policy/types/ec2CustomEventPatternsExcludedRoles"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-ec2#/policy/types/ec2CustomEventPatternsExcludedRoles"
Get Policy TypeGet Policy Settings