diff --git a/hugo/content/en/api/v2/security-monitoring/examples.json b/hugo/content/en/api/v2/security-monitoring/examples.json index c0c490224a3..2d9aa8a17f1 100644 --- a/hugo/content/en/api/v2/security-monitoring/examples.json +++ b/hugo/content/en/api/v2/security-monitoring/examples.json @@ -13399,6 +13399,17 @@ "data": [ { "attributes": { + "attributes": { + "workflow": { + "first_seen": "2020-06-23T14:46:01.000Z", + "last_seen": "2020-06-23T14:46:49.000Z", + "rule": { + "id": "0f5-e0c-805", + "name": "Brute Force Attack Grouped By User", + "version": 12 + } + } + }, "custom": { "workflow": { "first_seen": "2020-06-23T14:46:01.000Z", @@ -13425,12 +13436,15 @@ "next": "https://app.datadoghq.com/api/v2/security_monitoring/signals?filter[query]=foo&page[cursor]=eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==" }, "meta": { + "elapsed": 132, "page": { "after": "eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==" - } + }, + "request_id": "example-request-id", + "status": "done" } }, - "html": "
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
elapsed
\nint64
The time elapsed in milliseconds.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
request_id
\nstring
The unique identifier of the request.
status
\nstring
The status of the response.
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
elapsed
\nint64
The time elapsed in milliseconds.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
request_id
\nstring
The unique identifier of the request.
status
\nstring
The status of the response.
data
\nobject
Object description of a security signal.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
data
\nobject
Object description of a security signal.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
elapsed
\nint64
The time elapsed in milliseconds.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
request_id
\nstring
The unique identifier of the request.
status
\nstring
The status of the response.
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
elapsed
\nint64
The time elapsed in milliseconds.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
request_id
\nstring
The unique identifier of the request.
status
\nstring
The status of the response.
data
\nobject
Object description of a security signal.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
data
\nobject
Object description of a security signal.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
custom
\nobject
A JSON object of attributes in the security signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
data
\n[object]
An array of security signals matching the request.
attributes
\nobject
The object containing all signal attributes and their\nassociated values.
attributes
\nobject
A JSON object of attributes in the security signal, returned when listing or searching signals.
custom
\nobject
A JSON object of attributes in the security signal, returned when retrieving a single signal.
message
\nstring
The message in the security signal defined by the rule that generated the signal.
tags
\n[string]
An array of tags associated with the security signal.
timestamp
\ndate-time
The timestamp of the security signal.
id
\nstring
The unique ID of the security signal.
type
\nenum
The type of event. \nAllowed enum values: signal
default: signal
links
\nobject
Links attributes.
next
\nstring
The link for the next set of results. Note: The request can also be made using the\nPOST endpoint.
meta
\nobject
Meta attributes.
elapsed
\nint64
The time elapsed in milliseconds.
page
\nobject
Paging attributes.
after
\nstring
The cursor used to get the next results, if any. To make the next request, use the same\nparameters with the addition of the page[cursor].
request_id
\nstring
The unique identifier of the request.
status
\nstring
The status of the response.