Amazon S3 Storage Lens 사용을 위한 도우미 파일
Amazon S3 Storage Lens 사용을 위한 도우미 파일
예제에서 사용할 다음 JSON 파일과 그 주요 입력 값을 활용하세요.
본문
JSON의 S3 Storage Lens 예제 구성
config.json 파일은 S3 Storage Lens Organizations 수준 고급 지표 및 권장사항 구성의 상세 내용을 담아요. 다음 예제를 사용하려면 사용자 입력 자리 표시자를 자신의 정보로 교체하세요.
고급 지표와 권장사항에는 추가 요금이 적용돼요. 자세한 내용은 고급 지표 및 권장사항을 참고하세요.
{
"Id": " SampleS3StorageLensConfiguration ", //Use this property to identify your S3 Storage Lens configuration.
"AwsOrg": { //Use this property when enabling S3 Storage Lens for AWS Organizations.
"Arn": "arn:aws:organizations:: 123456789012 :organization/ o-abcdefgh "
},
"AccountLevel": {
"ActivityMetrics": {
"IsEnabled": true
},
"AdvancedCostOptimizationMetrics": {
"IsEnabled": true
},
"AdvancedDataProtectionMetrics": {
"IsEnabled": true
},
"DetailedStatusCodesMetrics": {
"IsEnabled": true
},
"BucketLevel": {
"ActivityMetrics": {
"IsEnabled": true
},
"AdvancedDataProtectionMetrics": {
"IsEnabled": true
},
"AdvancedCostOptimizationMetrics": {
"IsEnabled": true
},
"DetailedStatusCodesMetrics": {
"IsEnabled": true
},
"PrefixLevel": {
"StorageMetrics": {
"IsEnabled": true ,
"SelectionCriteria": {
"MaxDepth": 5 ,
"MinStorageBytesPercentage": 1.25 ,
"Delimiter":" / "
}
}
}
}
},
"Exclude": { //Replace with "Include" if you prefer to include Regions.
"Regions": [
" eu-west-1 "
],
"Buckets": [ //This attribute is not supported for AWS Organizations-level configurations.
"arn:aws:s3::: amzn-s3-demo-source-bucket "
]
},
"IsEnabled": true, //Whether the configuration is enabled
"DataExport": { //Details about the metrics export
"S3BucketDestination": {
"OutputSchemaVersion": " V_1 ",
"Format": " CSV ", //You can add "Parquet" if you prefer.
"AccountId": " 111122223333 ",
"Arn": "arn:aws:s3::: amzn-s3-demo-destination-bucket ", // The destination bucket for your metrics export must be in the same Region as your S3 Storage Lens configuration.
"Prefix": " prefix-for-your-export-destination ",
"Encryption": {
"SSES3": { }
}
},
"CloudWatchMetrics": {
"IsEnabled": true
}
}
}
Storage Lens 그룹이 있는 JSON의 S3 Storage Lens 예제 구성
config.json 파일은 Storage Lens 그룹을 사용할 때 Storage Lens 구성에 적용하려는 상세 내용을 담아요. 예제를 사용하려면 사용자 입력 자리 표시자를 자신의 정보로 교체하세요.
모든 Storage Lens 그룹을 대시보드에 연결하려면 다음 구문으로 Storage Lens 구성을 업데이트하세요.
{
"Id": "ExampleS3StorageLensConfiguration",
"AccountLevel": {
"ActivityMetrics": { "IsEnabled": true },
"AdvancedCostOptimizationMetrics": { "IsEnabled": true },
"AdvancedDataProtectionMetrics": { "IsEnabled":true
},
"BucketLevel": {
"ActivityMetrics": { "IsEnabled": true },
"StorageLensGroupLevel": { },
"IsEnabled": true }
Storage Lens 대시보드 구성에 Storage Lens 그룹 두 개(slg-1과 slg-2)만 포함하려면 다음 구문을 사용하세요.
{
"Id": " ExampleS3StorageLensConfiguration ",
"AccountLevel": {
"ActivityMetrics": { "IsEnabled": true },
"AdvancedCostOptimizationMetrics": { "IsEnabled": true },
"AdvancedDataProtectionMetrics": { "IsEnabled": true },
"BucketLevel": {
"ActivityMetrics": { "IsEnabled": true },
"StorageLensGroupLevel": {
"SelectionCriteria": {
"Include": [
"arn:aws:s3: us-east-1 : 111122223333 :storage-lens-group/ slg-1 ",
"arn:aws:s3: us-east-1 : 444455556666 :storage-lens-group/ slg-2 "
]
},
"IsEnabled": true }
일부 Storage Lens 그룹만 대시보드 구성에 연결되지 않도록 제외하려면 다음 구문을 사용하세요.
{
"Id": " ExampleS3StorageLensConfiguration ",
"AccountLevel": {
"ActivityMetrics": { "IsEnabled": true },
"AdvancedCostOptimizationMetrics": { "IsEnabled": true },
"AdvancedDataProtectionMetrics": { "IsEnabled": true },
"BucketLevel": {
"ActivityMetrics": { "IsEnabled": true },
"StorageLensGroupLevel": {
"SelectionCriteria": {
"Exclude": [
"arn:aws:s3: us-east-1 : 111122223333 :storage-lens-group/ slg-1 ",
"arn:aws:s3: us-east-1 : 444455556666 :storage-lens-group/ slg-2 "
]
},
"IsEnabled": true }
JSON의 S3 Storage Lens 예제 태그 구성
tags.json 파일은 S3 Storage Lens 구성에 적용하려는 태그를 담아요. 이 예제를 사용하려면 사용자 입력 자리 표시자를 자신의 정보로 교체하세요.
[
{
"Key": " key1 ",
"Value": " value1 "
},
{
"Key": " key2 ",
"Value": " value2 "
}
]
S3 Storage Lens 예제 구성 IAM 권한
예제 permissions.json – 특정 대시보드 이름 – 이 예제 정책은 특정 대시보드 이름이 지정된 S3 Storage Lens IAM permissions.json 파일을 보여줘요. value1, us-east-1, your-dashboard-name, example-account-id를 자신의 값으로 교체하세요.
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetStorageLensConfiguration",
"s3:DeleteStorageLensConfiguration",
"s3:PutStorageLensConfiguration"
],
"Condition": {
"StringEquals": {
"aws:ResourceTag/key1": " value1 "
}
},
"Resource": "arn:aws:s3: us-east-1 : 111122223333 :storage-lens/ your-dashboard-name "
}
]
}
예제 permissions.json – 특정 대시보드 이름 없음 – 이 예제 정책은 특정 대시보드 이름이 지정되지 않은 S3 Storage Lens IAM permissions.json 파일을 보여줘요. value1, us-east-1, example-account-id를 자신의 값으로 교체하세요.
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetStorageLensConfiguration",
"s3:DeleteStorageLensConfiguration",
"s3:PutStorageLensConfiguration"
],
"Condition": {
"StringEquals": {
"aws:ResourceTag/key1": " value1 "
}
},
"Resource": "arn:aws:s3: us-east-1 : 111122223333 :storage-lens/*"
}
]
}