IT审计师求助:如何用AWS CLI查询EC2实例关联的安全组
Hey there! As an IT auditor just getting up to speed with AWS operations, I totally get how critical it is to build efficient, reliable queries for your audit workflows. Let's sort out that incomplete CLI command and give you some extra tips to make your audit tasks smoother.
First, let's address the gaps in your original command:
- It got truncated at
SecurityGroups[... - Since each EC2 instance can be linked to multiple security groups, directly referencing
SecurityGroups[].GroupNamereturns an array—this can make output messy for audit reports. We'll fix that by flattening the array into a readable string.
Finalized CLI Command (Human-Readable Output)
Here's a polished version that pulls instance IDs, security group names, and security group IDs, formatted into a clean table perfect for audit reviews:
aws ec2 describe-instances --query 'Reservations[*].Instances[*].{Instance_ID:InstanceId, SecurityGroup_Names:join(", ", SecurityGroups[].GroupName), SecurityGroup_IDs:join(", ", SecurityGroups[].GroupId)}' --output table
Breakdown of Key Changes:
join(", ", SecurityGroups[].GroupName): Merges all security group names for an instance into a single comma-separated string (no more nested arrays cluttering your output)join(", ", SecurityGroups[].GroupId): Does the same for security group IDs, which are often needed for deeper security audits--output table: Renders results in a structured, easy-to-scan table format
Bonus: Audit-Focused Enhancements
If you want to add more context useful for audits (like instance state, names, or network details), use this expanded command:
aws ec2 describe-instances --query 'Reservations[*].Instances[*].{Instance_ID:InstanceId, Instance_Name:Tags[?Key==`Name`].Value | [0], Instance_State:State.Name, VPC_ID:VpcId, SecurityGroup_Names:join(", ", SecurityGroups[].GroupName), SecurityGroup_IDs:join(", ", SecurityGroups[].GroupId)}' --output table
This adds:
- Instance name (pulled from the
Nametag—showsnullif no name is set, which is a great audit flag for unlabeled resources) - Current instance state (running/stopped/terminated)
- VPC ID to track which network the instance belongs to
Exporting to CSV for Documentation
If you need to export results to a CSV file for your audit records, use this command (it outputs tab-separated text that you can easily save as CSV):
aws ec2 describe-instances --query 'Reservations[*].Instances[*].[InstanceId, Tags[?Key==`Name`].Value | [0], join(", ", SecurityGroups[].GroupName), join(", ", SecurityGroups[].GroupId)]' --output text > ec2-security-group-audit.csv
Filtering for Specific Instances
If you only want to audit running instances (a common use case), add a filter to narrow results:
aws ec2 describe-instances --filters "Name=instance-state-name,Values=running" --query 'Reservations[*].Instances[*].{Instance_ID:InstanceId, SecurityGroup_Names:join(", ", SecurityGroups[].GroupName), SecurityGroup_IDs:join(", ", SecurityGroups[].GroupId)}' --output table
内容的提问来源于stack exchange,提问作者Joey LoSurdo

