HEX
Server: Apache/2.4.41 (Ubuntu)
System: Linux ip-172-31-42-149 5.15.0-1084-aws #91~20.04.1-Ubuntu SMP Fri May 2 07:00:04 UTC 2025 aarch64
User: ubuntu (1000)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: //proc/self/root/usr/local/aws-cli/v2/dist/awscli/examples/securityhub/batch-update-findings.rst
**Example 1: To update a finding**

The following ``batch-update-findings`` example updates two findings to add a note, change the severity label, and resolve it. ::

    aws securityhub batch-update-findings \
        --finding-identifiers '[{"Id": "arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111", "ProductArn": "arn:aws:securityhub:us-west-1::product/aws/securityhub"}, {"Id": "arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222", "ProductArn": "arn:aws:securityhub:us-west-1::product/aws/securityhub"}]' \
        --note '{"Text": "Known issue that is not a risk.", "UpdatedBy": "user1"}' \
        --severity '{"Label": "LOW"}' \
        --workflow '{"Status": "RESOLVED"}'

Output::

    {
        "ProcessedFindings": [
            {
                "Id": "arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
                "ProductArn": "arn:aws:securityhub:us-west-1::product/aws/securityhub"
            },
            {
                "Id": "arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",
                "ProductArn": "arn:aws:securityhub:us-west-1::product/aws/securityhub"
            }
        ],
        "UnprocessedFindings": []
    }

For more information, see `Using BatchUpdateFindings to update a finding <https://docs.aws.amazon.com/securityhub/latest/userguide/finding-update-batchupdatefindings.html>`__ in the *AWS Security Hub User Guide*.

**Example 2: To update a finding using shorthand syntax**

The following ``batch-update-findings`` example updates two findings to add a note, change the severity label, and resolve it using shorthand syntax. ::

    aws securityhub batch-update-findings \
        --finding-identifiers Id="arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",ProductArn="arn:aws:securityhub:us-west-1::product/aws/securityhub" Id="arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",ProductArn="arn:aws:securityhub:us-west-1::product/aws/securityhub" \
        --note Text="Known issue that is not a risk.",UpdatedBy="user1" \
        --severity Label="LOW" \
        --workflow Status="RESOLVED"

Output::

    {
        "ProcessedFindings": [
            {
                "Id": "arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
                "ProductArn": "arn:aws:securityhub:us-west-1::product/aws/securityhub"
            },
            {
                "Id": "arn:aws:securityhub:us-west-1:123456789012:subscription/pci-dss/v/3.2.1/PCI.Lambda.2/finding/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",
                "ProductArn": "arn:aws:securityhub:us-west-1::product/aws/securityhub"
            }
        ],
        "UnprocessedFindings": []
    }

For more information, see `Using BatchUpdateFindings to update a finding <https://docs.aws.amazon.com/securityhub/latest/userguide/finding-update-batchupdatefindings.html>`__ in the *AWS Security Hub User Guide*.