Evaluating Your Resources - Amazon Config
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China.

Evaluating Your Resources

When you create custom rules or use managed rules, Amazon Config evaluates your resources against those rules. You can run on-demand evaluations for resources against your rules. For example, this is helpful when you create a custom rule and want to verify that Amazon Config is correctly evaluating your resources or to identify if there is an issue with the evaluation logic of your Amazon Lambda function.

Example

  1. You create a custom rule that evaluates whether your IAM users have active access keys.

  2. Amazon Config evaluates the resources against your custom rule.

  3. An IAM user who doesn't have an active access key exists in your account. Your rule doesn't correctly flag this resource as noncompliant.

  4. You fix the rule and start the evaluation again.

  5. Because you fixed your rule, the rule correctly evaluates your resources, and flags the IAM user resource as noncompliant.

Evaluating your Resources (Console)

  1. Sign in to the Amazon Web Services Management Console and open the Amazon Config console at https://console.amazonaws.cn/config/.

  2. In the Amazon Web Services Management Console menu, verify that the region selector is set to a region that supports Amazon Config rules. For the list of supported regions, see Amazon Config Regions and Endpoints in the Amazon Web Services General Reference.

  3. In the navigation pane, choose Rules. The Rules page shows the name, associated remediation action, and compliance status of each rule.

  4. Choose a rule from the table.

  5. From the Actions dropdown list, choose Re-evaluate.

  6. Amazon Config starts evaluating the resources against your rule.

Note

You can re-evaluate a rule once per minute. You must wait for Amazon Config to complete the evaluation for your rule before you start another evaluation. You can't run an evaluation if at the same time the rule is being updated or if the rule is being deleted.

Evaluating your Resources (CLI)

  • Use the start-config-rules-evaluation command.

    $ aws configservice start-config-rules-evaluation --config-rule-names ConfigRuleName

    Amazon Config starts evaluating the recorded resource configurations against your rule.

    You can also specify multiple rules in your request.

    aws configservice start-config-rules-evaluation --config-rule-names ConfigRuleName1 ConfigRuleName2 ConfigRuleName3

Evaluating your Resources (API)

Use the StartConfigRulesEvaluation action.