Optional additionalA container for additional, undeclared properties. This is a holder for any undeclared properties as specified with the 'additionalProperties' keyword in the OAS document.
Optional calculatedCalculated fields. Only allowed for scheduled rules - in other words, when schedulingOptions is also defined.
Optional casesCases for generating signals.
Optional complianceHow to generate compliance signals. Useful for cloud_configuration rules only.
Optional createdWhen the rule was created, timestamp in milliseconds.
Optional creationUser ID of the user who created the rule.
Optional customCustom/Overridden message for generated signals (used in case of Default rule update).
Optional customCustom/Overridden name of the rule (used in case of Default rule update).
Optional defaultDefault Tags for default rules (included in tags)
Optional deprecationWhen the rule will be deprecated, timestamp in milliseconds.
Optional filtersAdditional queries to filter matched events before they are processed. This field is deprecated for log detection, signal correlation, and workload security rules.
Optional groupAdditional grouping to perform on top of the existing groups in the query section. Must be a subset of the existing groups.
Optional hasWhether the notifications include the triggering group-by values in their title.
Optional idThe ID of the rule.
Optional isWhether the rule is included by default.
Optional isWhether the rule has been deleted.
Optional isWhether the rule is enabled.
Optional messageMessage for generated signals.
Optional nameThe name of the rule.
Optional optionsOptions.
Optional queriesQueries for selecting logs which are part of the rule.
Optional referenceReference tables for the rule.
Optional schedulingOptions for scheduled rules. When this field is present, the rule runs based on the schedule. When absent, it runs real-time on ingested logs.
Optional tagsTags for generated signals.
Optional thirdCases for generating signals from third-party rules. Only available for third-party rules.
Optional typeThe rule type.
Optional updateUser ID of the user who updated the rule.
Optional updatedThe date the rule was last updated, in milliseconds.
Optional versionThe version of the rule.
Generated using TypeDoc
Rule.