Optional
additionalA container for additional, undeclared properties. This is a holder for any undeclared properties as specified with the 'additionalProperties' keyword in the OAS document.
Cases for generating signals.
Optional
filtersAdditional queries to filter matched events before they are processed. This field is deprecated for log detection, signal correlation, and workload security rules.
Optional
hasWhether the notifications include the triggering group-by values in their title.
Whether the rule is enabled.
Message for generated signals.
The name of the rule.
Options.
Queries for selecting logs which are part of the rule.
Optional
referenceReference tables for the rule.
Optional
tagsTags for generated signals.
Optional
thirdCases for generating signals from third-party rules. Only available for third-party rules.
Optional
typeThe rule type.
Generated using TypeDoc
Create a new rule.