CINXE.COM
Running sensitive data discovery jobs - Amazon Macie
<!DOCTYPE html> <html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>Running sensitive data discovery jobs - Amazon Macie</title><meta name="viewport" content="width=device-width,initial-scale=1" /><meta name="assets_root" content="/assets" /><meta name="target_state" content="discovery-jobs" /><meta name="default_state" content="discovery-jobs" /><link rel="icon" type="image/ico" href="/assets/images/favicon.ico" /><link rel="shortcut icon" type="image/ico" href="/assets/images/favicon.ico" /><link rel="canonical" href="https://docs.aws.amazon.com/macie/latest/user/discovery-jobs.html" /><meta name="description" content="Learn about options for creating and configuring sensitive data discovery jobs in Amazon Macie to detect and report sensitive data." /><meta name="deployment_region" content="IAD" /><meta name="product" content="Amazon Macie" /><meta name="guide" content="User Guide" /><meta name="abstract" content="Amazon Macie is a fully managed data security and data privacy service. Macie uses machine learning and pattern matching to help you discover, monitor, and protect your sensitive data in Amazon S3." /><meta name="guide-locale" content="en_us" /><meta name="tocs" content="toc-contents.json" /><link rel="canonical" href="https://docs.aws.amazon.com/macie/latest/user/discovery-jobs.html" /><link rel="alternative" href="https://docs.aws.amazon.com/id_id/macie/latest/user/discovery-jobs.html" hreflang="id-id" /><link rel="alternative" href="https://docs.aws.amazon.com/id_id/macie/latest/user/discovery-jobs.html" hreflang="id" /><link rel="alternative" href="https://docs.aws.amazon.com/de_de/macie/latest/user/discovery-jobs.html" hreflang="de-de" /><link rel="alternative" href="https://docs.aws.amazon.com/de_de/macie/latest/user/discovery-jobs.html" hreflang="de" /><link rel="alternative" href="https://docs.aws.amazon.com/macie/latest/user/discovery-jobs.html" hreflang="en-us" /><link rel="alternative" href="https://docs.aws.amazon.com/macie/latest/user/discovery-jobs.html" hreflang="en" /><link rel="alternative" href="https://docs.aws.amazon.com/es_es/macie/latest/user/discovery-jobs.html" hreflang="es-es" /><link rel="alternative" href="https://docs.aws.amazon.com/es_es/macie/latest/user/discovery-jobs.html" hreflang="es" /><link rel="alternative" href="https://docs.aws.amazon.com/fr_fr/macie/latest/user/discovery-jobs.html" hreflang="fr-fr" /><link rel="alternative" href="https://docs.aws.amazon.com/fr_fr/macie/latest/user/discovery-jobs.html" hreflang="fr" /><link rel="alternative" href="https://docs.aws.amazon.com/it_it/macie/latest/user/discovery-jobs.html" hreflang="it-it" /><link rel="alternative" href="https://docs.aws.amazon.com/it_it/macie/latest/user/discovery-jobs.html" hreflang="it" /><link rel="alternative" href="https://docs.aws.amazon.com/ja_jp/macie/latest/user/discovery-jobs.html" hreflang="ja-jp" /><link rel="alternative" href="https://docs.aws.amazon.com/ja_jp/macie/latest/user/discovery-jobs.html" hreflang="ja" /><link rel="alternative" href="https://docs.aws.amazon.com/ko_kr/macie/latest/user/discovery-jobs.html" hreflang="ko-kr" /><link rel="alternative" href="https://docs.aws.amazon.com/ko_kr/macie/latest/user/discovery-jobs.html" hreflang="ko" /><link rel="alternative" href="https://docs.aws.amazon.com/pt_br/macie/latest/user/discovery-jobs.html" hreflang="pt-br" /><link rel="alternative" href="https://docs.aws.amazon.com/pt_br/macie/latest/user/discovery-jobs.html" hreflang="pt" /><link rel="alternative" href="https://docs.aws.amazon.com/zh_cn/macie/latest/user/discovery-jobs.html" hreflang="zh-cn" /><link rel="alternative" href="https://docs.aws.amazon.com/zh_tw/macie/latest/user/discovery-jobs.html" hreflang="zh-tw" /><link rel="alternative" href="https://docs.aws.amazon.com/macie/latest/user/discovery-jobs.html" hreflang="x-default" /><meta name="feedback-item" content="Macie" /><meta name="this_doc_product" content="Amazon Macie" /><meta name="this_doc_guide" content="User Guide" /><script defer="" src="/assets/r/vendor4.js?version=2021.12.02"></script><script defer="" src="/assets/r/vendor3.js?version=2021.12.02"></script><script defer="" src="/assets/r/vendor1.js?version=2021.12.02"></script><script defer="" src="/assets/r/awsdocs-common.js?version=2021.12.02"></script><script defer="" src="/assets/r/awsdocs-doc-page.js?version=2021.12.02"></script><link href="/assets/r/vendor4.css?version=2021.12.02" rel="stylesheet" /><link href="/assets/r/awsdocs-common.css?version=2021.12.02" rel="stylesheet" /><link href="/assets/r/awsdocs-doc-page.css?version=2021.12.02" rel="stylesheet" /><script async="" id="awsc-panorama-bundle" type="text/javascript" src="https://prod.pa.cdn.uis.awsstatic.com/panorama-nav-init.js" data-config="{'appEntity':'aws-documentation','region':'us-east-1','service':'macie'}"></script><meta id="panorama-serviceSubSection" value="User Guide" /><meta id="panorama-serviceConsolePage" value="Running sensitive data discovery jobs" /></head><body class="awsdocs awsui"><div class="awsdocs-container"><awsdocs-header></awsdocs-header><awsui-app-layout id="app-layout" class="awsui-util-no-gutters" ng-controller="ContentController as $ctrl" header-selector="awsdocs-header" navigation-hide="false" navigation-width="$ctrl.navWidth" navigation-open="$ctrl.navOpen" navigation-change="$ctrl.onNavChange($event)" tools-hide="$ctrl.hideTools" tools-width="$ctrl.toolsWidth" tools-open="$ctrl.toolsOpen" tools-change="$ctrl.onToolsChange($event)"><div id="guide-toc" dom-region="navigation"><awsdocs-toc></awsdocs-toc></div><div id="main-column" dom-region="content" tabindex="-1"><awsdocs-view class="awsdocs-view"><div id="awsdocs-content"><head><title>Running sensitive data discovery jobs - Amazon Macie</title><meta name="pdf" content="/pdfs/macie/latest/user/macie-user-guide.pdf#discovery-jobs" /><meta name="rss" content="macie-user-guide.rss" /><meta name="forums" content="https://repost.aws/tags/TA_J7v39UoTdiBWCAlEs2svA" /><meta name="feedback" content="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=Macie&topic_url=https://docs.aws.amazon.com/en_us/macie/latest/user/discovery-jobs.html" /><meta name="feedback-yes" content="feedbackyes.html?topic_url=https://docs.aws.amazon.com/en_us/macie/latest/user/discovery-jobs.html" /><meta name="feedback-no" content="feedbackno.html?topic_url=https://docs.aws.amazon.com/en_us/macie/latest/user/discovery-jobs.html" /><meta name="keywords" content="classify data,data classification,data scans,find PII,inspect data,scan data,PII monitoring,PII scanning,sensitive data discovery,sensitive data detection,classification job,continual data classification,continual data scanning,data scanning,deep data scan,full data scan,on-demand data classification,on-demand data scans,on-demand scanning,periodic data classification,periodic data scans,scan data on demand,sensitive data discovery job" /><script type="application/ld+json"> { "@context" : "https://schema.org", "@type" : "BreadcrumbList", "itemListElement" : [ { "@type" : "ListItem", "position" : 1, "name" : "AWS", "item" : "https://aws.amazon.com" }, { "@type" : "ListItem", "position" : 2, "name" : "Macie", "item" : "https://docs.aws.amazon.com/macie/index.html" }, { "@type" : "ListItem", "position" : 3, "name" : "User Guide", "item" : "https://docs.aws.amazon.com/macie/latest/user" }, { "@type" : "ListItem", "position" : 4, "name" : "Discovering sensitive data with Macie", "item" : "https://docs.aws.amazon.com/macie/latest/user/data-classification.html" }, { "@type" : "ListItem", "position" : 5, "name" : "Running sensitive data discovery jobs", "item" : "https://docs.aws.amazon.com/macie/latest/user/data-classification.html" } ] } </script></head><body><div id="main"><div style="display: none"><a href="/pdfs/macie/latest/user/macie-user-guide.pdf#discovery-jobs" target="_blank" rel="noopener noreferrer" title="Open PDF"></a></div><div id="breadcrumbs" class="breadcrumb"><a href="/index.html">Documentation</a><a href="/macie/index.html">Macie</a><a href="what-is-macie.html">User Guide</a></div><div id="main-content" class="awsui-util-container"><div id="main-col-body"><awsdocs-language-banner data-service="$ctrl.pageService"></awsdocs-language-banner><h1 class="topictitle" id="discovery-jobs">Running sensitive data discovery jobs</h1><div class="awsdocs-page-header-container"><awsdocs-page-header></awsdocs-page-header><awsdocs-filter-selector id="awsdocs-filter-selector"></awsdocs-filter-selector></div><p>With Amazon Macie, you can create and run sensitive data discovery jobs to automate discovery, logging, and reporting of sensitive data in Amazon Simple Storage Service (Amazon S3) general purpose buckets. A <em>sensitive data discovery job</em> is a series of automated processing and analysis tasks that Macie performs to detect and report sensitive data in Amazon S3 objects. Each job provides detailed reports of the sensitive data that Macie finds and the analysis that Macie performs. By creating and running jobs, you can build and maintain a comprehensive view of the data that your organization stores in Amazon S3 and any security or compliance risks for that data.</p><p>To help you meet and maintain compliance with your data security and privacy requirements, Macie provides several options for scheduling and defining the scope of a job. You can configure a job to run only once for on-demand analysis and assessment, or on a recurring basis for periodic analysis, assessment, and monitoring. You also define the breadth and depth of a job's analysis—specific S3 buckets that you select or buckets that match specific criteria. You can optionally refine the scope of that analysis by choosing additional options. The options include custom criteria that derive from properties of S3 objects, such as tags, prefixes, and when an object was last modified.</p><p>For each job, you also specify the types of sensitive data that you want Macie to detect and report. You can configure a job to use <a href="./managed-data-identifiers.html">managed data identifiers</a> that Macie provides, <a href="./custom-data-identifiers.html">custom data identifiers</a> that you define, or a combination of the two. By selecting specific managed and custom data identifiers for a job, you can tailor the analysis to focus on specific types of sensitive data. To fine tune the analysis, you can also configure a job to use <a href="./allow-lists.html">allow lists</a>. Allow lists specify text and text patterns that you want Macie to ignore, typically sensitive data exceptions for your organization's particular scenarios or environment.</p><p>Each job produces records of the sensitive data that Macie finds and the analysis that Macie performs—<em>sensitive data findings</em> and <em>sensitive data discovery results</em>. A <em>sensitive data finding</em> is a detailed report of sensitive data that Macie found in an S3 object. A <em>sensitive data discovery result</em> is a record that logs details about the analysis of an S3 object. Macie creates a sensitive data discovery result for each object that you configure a job to analyze. This includes objects that Macie doesn’t find sensitive data in, and therefore don't produce sensitive data findings, and objects that Macie can't analyze due to errors or issues. Each type of record adheres to a standardized schema, which can help you query, monitor, and process the records to meet your security and compliance requirements.</p><div class="highlights"><h6>Topics</h6><ul><li><a href="./discovery-jobs-scope.html">Scope options for jobs</a></li><li><a href="./discovery-jobs-create.html">Creating a job</a></li><li><a href="./discovery-jobs-manage-results.html">Reviewing job results</a></li><li><a href="./discovery-jobs-manage.html">Managing jobs</a></li><li><a href="./discovery-jobs-monitor-cw-logs.html">Monitoring jobs with CloudWatch Logs</a></li><li><a href="./discovery-jobs-costs.html">Forecasting and monitoring job costs</a></li><li><a href="./discovery-jobs-mdis-recommended.html">Managed data identifiers recommended for jobs</a></li></ul></div><awsdocs-copyright class="copyright-print"></awsdocs-copyright><awsdocs-thumb-feedback right-edge="{{$ctrl.thumbFeedbackRightEdge}}"></awsdocs-thumb-feedback></div><noscript><div><div><div><div id="js_error_message"><p><img src="https://d1ge0kk1l5kms0.cloudfront.net/images/G/01/webservices/console/warning.png" alt="Warning" /> <strong>Javascript is disabled or is unavailable in your browser.</strong></p><p>To use the Amazon Web Services Documentation, Javascript must be enabled. Please refer to your browser's Help pages for instructions.</p></div></div></div></div></noscript><div id="main-col-footer" class="awsui-util-font-size-0"><div id="doc-conventions"><a target="_top" href="/general/latest/gr/docconventions.html">Document Conventions</a></div><div class="prev-next"><div id="previous" class="prev-link" accesskey="p" href="./discovery-asdd-settings-defaults.html">Default automated discovery settings</div><div id="next" class="next-link" accesskey="n" href="./discovery-jobs-scope.html">Scope options for jobs</div></div></div><awsdocs-page-utilities></awsdocs-page-utilities></div><div id="quick-feedback-yes" style="display: none;"><div class="title">Did this page help you? - Yes</div><div class="content"><p>Thanks for letting us know we're doing a good job!</p><p>If you've got a moment, please tell us what we did right so we can do more of it.</p><p><awsui-button id="fblink" rel="noopener noreferrer" target="_blank" text="Feedback" click="linkClick($event)" href="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=Macie&topic_url=https://docs.aws.amazon.com/en_us/macie/latest/user/discovery-jobs.html"></awsui-button></p></div></div><div id="quick-feedback-no" style="display: none;"><div class="title">Did this page help you? - No</div><div class="content"><p>Thanks for letting us know this page needs work. We're sorry we let you down.</p><p>If you've got a moment, please tell us how we can make the documentation better.</p><p><awsui-button id="fblink" rel="noopener noreferrer" target="_blank" text="Feedback" click="linkClick($event)" href="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=Macie&topic_url=https://docs.aws.amazon.com/en_us/macie/latest/user/discovery-jobs.html"></awsui-button></p></div></div></div></body></div></awsdocs-view><div class="page-loading-indicator" id="page-loading-indicator"><awsui-spinner size="large"></awsui-spinner></div></div><div id="tools-panel" dom-region="tools"><awsdocs-tools-panel id="awsdocs-tools-panel"></awsdocs-tools-panel></div></awsui-app-layout><awsdocs-cookie-banner class="doc-cookie-banner"></awsdocs-cookie-banner></div></body></html>