HEX
Server: Apache/2.4.41 (Ubuntu)
System: Linux ip-172-31-42-149 5.15.0-1084-aws #91~20.04.1-Ubuntu SMP Fri May 2 07:00:04 UTC 2025 aarch64
User: ubuntu (1000)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: //usr/local/aws-cli/v2/current/current/current/dist/awscli/examples/securityhub/update-insight.rst
**Example 1: To change the filter for a custom insight**

The following ``update-insight`` example changes the filters for a custom insight. The updated insight looks for findings with a high severity that are related to AWS roles. ::

    aws securityhub update-insight \
        --insight-arn "arn:aws:securityhub:us-west-1:123456789012:insight/123456789012/custom/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111" \
        --filters '{"ResourceType": [{ "Comparison": "EQUALS", "Value": "AwsIamRole"}], "SeverityLabel": [{"Comparison": "EQUALS", "Value": "HIGH"}]}' \
        --name "High severity role findings"

**Example 2: To change the grouping attribute for a custom insight**

The following ``update-insight`` example changes the grouping attribute for the custom insight with the specified ARN. The new grouping attribute is the resource ID. ::

    aws securityhub update-insight \
        --insight-arn "arn:aws:securityhub:us-west-1:123456789012:insight/123456789012/custom/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111" \
        --group-by-attribute "ResourceId" \
        --name "Critical role findings"

Output::

    {
        "Insights": [
            {
                "InsightArn": "arn:aws:securityhub:us-west-1:123456789012:insight/123456789012/custom/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
                "Name": "Critical role findings",
                "Filters": {
                    "SeverityLabel": [
                        {
                            "Value": "CRITICAL",
                            "Comparison": "EQUALS"
                        }
                    ],
                    "ResourceType": [
                        {
                            "Value": "AwsIamRole",
                            "Comparison": "EQUALS"
                        }
                    ]
                },
                "GroupByAttribute": "ResourceId"
            }
        ]
    }

For more information, see `Managing custom insights <https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-custom-insights.html>`__ in the *AWS Security Hub User Guide*.