Optional
additionalA container for additional, undeclared properties. This is a holder for any undeclared properties as specified with the 'additionalProperties' keyword in the OAS document.
Optional
calculatedCalculated fields.
Cases used for generating job results.
Optional
filtersAdditional queries to filter matched events before they are processed. This field is deprecated for log detection, signal correlation, and workload security rules.
Starting time of data analyzed by the job.
Index used to load the data.
Message for generated results.
Job name.
Optional
optionsOptions on rules.
Queries for selecting logs analyzed by the job.
Optional
referenceReference tables for the rule.
Optional
tagsTags for generated signals.
Optional
thirdCases for generating results from third-party rules. Only available for third-party rules.
Ending time of data analyzed by the job.
Optional
typeJob type.
Generated using TypeDoc
Definition of a historical job.