Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .generator/schemas/v2/openapi.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -114666,6 +114666,19 @@ components:
type: string
dataSource:
$ref: "#/components/schemas/SecurityMonitoringStandardDataSource"
datasetIds:
description: IDs of the datasets queried by the rule. Only used when `queryLanguage` is `sql`.
items:
description: Dataset ID.
type: string
type: array
datasetVersions:
additionalProperties:
description: Dataset version.
format: int64
type: integer
description: Version of each dataset used by the rule, keyed by dataset ID. Only used when `queryLanguage` is `sql`.
type: object
distinctFields:
description: Field for which the cardinality is measured. Sent as an array.
items:
Expand Down Expand Up @@ -114709,6 +114722,10 @@ components:
description: Query to run on logs.
example: a > 3
type: string
queryLanguage:
description: Language of the query. Use `sql` for SQL-based rules over datasets. Defaults to `event_query`.
example: sql
type: string
type: object
SecurityMonitoringStandardRuleResponse:
description: Rule.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,12 @@ def __init__(self, **kwargs):
:param data_source: Source of events, either logs, audit trail, security signals, or Datadog events. `app_sec_spans` is deprecated in favor of `spans`.
:type data_source: SecurityMonitoringStandardDataSource, optional

:param dataset_ids: IDs of the datasets queried by the rule. Only used when `queryLanguage` is `sql`.
:type dataset_ids: [str], optional

:param dataset_versions: Version of each dataset used by the rule, keyed by dataset ID. Only used when `queryLanguage` is `sql`.
:type dataset_versions: {str: (int,)}, optional

:param distinct_fields: Field for which the cardinality is measured. Sent as an array.
:type distinct_fields: [str], optional

Expand Down Expand Up @@ -53,6 +59,9 @@ def __init__(self, **kwargs):
:param query: Query to run on logs.
:type query: str, optional

:param query_language: Language of the query. Use `sql` for SQL-based rules over datasets. Defaults to `event_query`.
:type query_language: str, optional

:param correlated_by_fields: Fields to group by.
:type correlated_by_fields: [str], optional

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
# Copyright 2019-Present Datadog, Inc.
from __future__ import annotations

from typing import List, Union, TYPE_CHECKING
from typing import Dict, List, Union, TYPE_CHECKING

from datadog_api_client.model_utils import (
ModelNormal,
Expand Down Expand Up @@ -36,6 +36,8 @@ def openapi_types(_):
"aggregation": (SecurityMonitoringRuleQueryAggregation,),
"custom_query_extension": (str,),
"data_source": (SecurityMonitoringStandardDataSource,),
"dataset_ids": ([str],),
"dataset_versions": ({str: (int,)},),
"distinct_fields": ([str],),
"group_by_fields": ([str],),
"has_optional_group_by_fields": (bool,),
Expand All @@ -45,12 +47,15 @@ def openapi_types(_):
"metrics": ([str],),
"name": (str,),
"query": (str,),
"query_language": (str,),
}

attribute_map = {
"aggregation": "aggregation",
"custom_query_extension": "customQueryExtension",
"data_source": "dataSource",
"dataset_ids": "datasetIds",
"dataset_versions": "datasetVersions",
"distinct_fields": "distinctFields",
"group_by_fields": "groupByFields",
"has_optional_group_by_fields": "hasOptionalGroupByFields",
Expand All @@ -60,13 +65,16 @@ def openapi_types(_):
"metrics": "metrics",
"name": "name",
"query": "query",
"query_language": "queryLanguage",
}

def __init__(
self_,
aggregation: Union[SecurityMonitoringRuleQueryAggregation, UnsetType] = unset,
custom_query_extension: Union[str, UnsetType] = unset,
data_source: Union[SecurityMonitoringStandardDataSource, UnsetType] = unset,
dataset_ids: Union[List[str], UnsetType] = unset,
dataset_versions: Union[Dict[str, int], UnsetType] = unset,
distinct_fields: Union[List[str], UnsetType] = unset,
group_by_fields: Union[List[str], UnsetType] = unset,
has_optional_group_by_fields: Union[bool, UnsetType] = unset,
Expand All @@ -76,6 +84,7 @@ def __init__(
metrics: Union[List[str], UnsetType] = unset,
name: Union[str, UnsetType] = unset,
query: Union[str, UnsetType] = unset,
query_language: Union[str, UnsetType] = unset,
**kwargs,
):
"""
Expand All @@ -90,6 +99,12 @@ def __init__(
:param data_source: Source of events, either logs, audit trail, security signals, or Datadog events. ``app_sec_spans`` is deprecated in favor of ``spans``.
:type data_source: SecurityMonitoringStandardDataSource, optional

:param dataset_ids: IDs of the datasets queried by the rule. Only used when ``queryLanguage`` is ``sql``.
:type dataset_ids: [str], optional

:param dataset_versions: Version of each dataset used by the rule, keyed by dataset ID. Only used when ``queryLanguage`` is ``sql``.
:type dataset_versions: {str: (int,)}, optional

:param distinct_fields: Field for which the cardinality is measured. Sent as an array.
:type distinct_fields: [str], optional

Expand Down Expand Up @@ -118,13 +133,20 @@ def __init__(

:param query: Query to run on logs.
:type query: str, optional

:param query_language: Language of the query. Use ``sql`` for SQL-based rules over datasets. Defaults to ``event_query``.
:type query_language: str, optional
"""
if aggregation is not unset:
kwargs["aggregation"] = aggregation
if custom_query_extension is not unset:
kwargs["custom_query_extension"] = custom_query_extension
if data_source is not unset:
kwargs["data_source"] = data_source
if dataset_ids is not unset:
kwargs["dataset_ids"] = dataset_ids
if dataset_versions is not unset:
kwargs["dataset_versions"] = dataset_versions
if distinct_fields is not unset:
kwargs["distinct_fields"] = distinct_fields
if group_by_fields is not unset:
Expand All @@ -143,4 +165,6 @@ def __init__(
kwargs["name"] = name
if query is not unset:
kwargs["query"] = query
if query_language is not unset:
kwargs["query_language"] = query_language
super().__init__(kwargs)
Loading