상관 규칙
상관 규칙에 대한 REST API 작업
개요
필요 권한
작업
the pagination token
the maximum results to return
100Substring search by name (case-insensitive)
Only include rules in the given state
Only include rules with one of the given tags (case-insensitive)
Only include rules whose creator matches this user ID or actor ID
Only include rules last modified by this user ID or actor ID
OK response.
pagination token for the next page of results
OK response.
set this field to false to exclude running tests prior to saving
trueset this field to true if you want to run tests without saving
falseDetermines whether the rule should create alerts when it triggers
The amount of time in minutes for grouping alerts
60The description of the correlation rule
The yaml representation of the correlation rule
The display name of the correlation rule
Determines whether or not the correlation rule is active
The id of the correlation rule
Destination IDs that override default alert routing based on severity
How to handle the generated alert
A list of fields in the event to create top 5 summaries for
The tags for the correlation rule
the number of events that must match before an alert is triggered
1OK response.
The IDs of the rules referenced by this correlation rule
Determines whether the rule should create alerts when it triggers
The text of the user-provided CreatedBy field when uploaded via CI/CD
The amount of time in minutes for grouping alerts
60The description of the correlation rule
The yaml representation of the correlation rule
The display name of the correlation rule
Determines whether or not the correlation rule is active
The id of the correlation rule
The log types derived from the correlation rule references
Determines if the correlation rule is managed by panther
Destination IDs that override default alert routing based on severity
How to handle the generated alert
A list of fields in the event to create top 5 summaries for
The tags for the correlation rule
the number of events that must match before an alert is triggered
1No Content response.
bad_request: Bad Request response.
exists: Conflict response.
ID of the correlation rule to fetch
OK response.
The IDs of the rules referenced by this correlation rule
Determines whether the rule should create alerts when it triggers
The text of the user-provided CreatedBy field when uploaded via CI/CD
The amount of time in minutes for grouping alerts
60The description of the correlation rule
The yaml representation of the correlation rule
The display name of the correlation rule
Determines whether or not the correlation rule is active
The id of the correlation rule
The log types derived from the correlation rule references
Determines if the correlation rule is managed by panther
Destination IDs that override default alert routing based on severity
How to handle the generated alert
A list of fields in the event to create top 5 summaries for
The tags for the correlation rule
the number of events that must match before an alert is triggered
1not_found: Not Found response.
the id of the correlation rule
set this field to false to exclude running tests prior to saving
trueset this field to true if you want to run tests without saving
falseDetermines whether the rule should create alerts when it triggers
The amount of time in minutes for grouping alerts
60The description of the correlation rule
The yaml representation of the correlation rule
The display name of the correlation rule
Determines whether or not the correlation rule is active
The id of the correlation rule
Destination IDs that override default alert routing based on severity
How to handle the generated alert
A list of fields in the event to create top 5 summaries for
The tags for the correlation rule
the number of events that must match before an alert is triggered
1200 returned if the item already existed
The IDs of the rules referenced by this correlation rule
Determines whether the rule should create alerts when it triggers
The text of the user-provided CreatedBy field when uploaded via CI/CD
The amount of time in minutes for grouping alerts
60The description of the correlation rule
The yaml representation of the correlation rule
The display name of the correlation rule
Determines whether or not the correlation rule is active
The id of the correlation rule
The log types derived from the correlation rule references
Determines if the correlation rule is managed by panther
Destination IDs that override default alert routing based on severity
How to handle the generated alert
A list of fields in the event to create top 5 summaries for
The tags for the correlation rule
the number of events that must match before an alert is triggered
1201 returned if the item was created
No Content response.
bad_request: Bad Request response.
ID of the correlation rule to delete
No Content response.
bad_request: Bad Request response.
not_found: Not Found response.
No content
마지막 업데이트
도움이 되었나요?

