@@ -60787,19 +60787,23 @@ components:
6078760787 - DONE
6078860788 - TIMEOUT
6078960789 SecurityMonitoringContentPackActivation:
60790- description: The activation status of a content pack
60790+ description: The activation lifecycle state of a content pack.
6079160791 enum:
6079260792 - never_activated
6079360793 - activated
6079460794 - deactivated
6079560795 example: activated
6079660796 type: string
60797+ x-enum-descriptions:
60798+ - Pack has never been activated for this organization.
60799+ - Pack is currently activated.
60800+ - Pack was previously activated but has since been deactivated.
6079760801 x-enum-varnames:
6079860802 - NEVER_ACTIVATED
6079960803 - ACTIVATED
6080060804 - DEACTIVATED
6080160805 SecurityMonitoringContentPackIntegrationStatus:
60802- description: The installation status of the related integration
60806+ description: The installation status of the related Datadog integration.
6080360807 enum:
6080460808 - installed
6080560809 - available
@@ -60808,6 +60812,12 @@ components:
6080860812 - error
6080960813 example: installed
6081060814 type: string
60815+ x-enum-descriptions:
60816+ - Integration is fully installed.
60817+ - Integration exists in the catalog but is not installed.
60818+ - Integration is only partially configured.
60819+ - Integration detected (for example, logs are flowing) but not explicitly installed.
60820+ - Integration is in an error state.
6081160821 x-enum-varnames:
6081260822 - INSTALLED
6081360823 - AVAILABLE
@@ -60824,15 +60834,16 @@ components:
6082460834 cp_activation:
6082560835 $ref: "#/components/schemas/SecurityMonitoringContentPackActivation"
6082660836 filters_configured_for_logs:
60827- description: Whether filters (Security Filters or Index Query depending on the pricing model) are configured for logs
60837+ description: Whether filters (Security Filters or Index Query depending on the pricing model) are present and correctly configured to route logs into Cloud SIEM.
6082860838 example: true
6082960839 type: boolean
6083060840 integration_installed_status:
6083160841 $ref: "#/components/schemas/SecurityMonitoringContentPackIntegrationStatus"
6083260842 logs_last_collected:
6083360843 $ref: "#/components/schemas/SecurityMonitoringContentPackTimestampBucket"
6083460844 logs_seen_from_any_index:
60835- description: Whether logs have been seen from any index
60845+ description: >-
60846+ Whether logs for this content pack have been seen in any Datadog index within the last 72 hours, regardless of whether the Cloud SIEM filter is configured.
6083660847 example: true
6083760848 type: boolean
6083860849 state:
@@ -60897,7 +60908,7 @@ components:
6089760908 - meta
6089860909 type: object
6089960910 SecurityMonitoringContentPackStatus:
60900- description: The current status of a content pack
60911+ description: The current operational status of a content pack.
6090160912 enum:
6090260913 - install
6090360914 - activate
@@ -60907,6 +60918,13 @@ components:
6090760918 - broken
6090860919 example: active
6090960920 type: string
60921+ x-enum-descriptions:
60922+ - Not activated; no logs detected in the last 72 hours.
60923+ - Not activated; logs are flowing into a Datadog index but not yet routed through Cloud SIEM.
60924+ - Activated; awaiting first log ingestion.
60925+ - Activated; logs received within the last 24 hours.
60926+ - Activated; integration not installed or logs last seen 24 to 72 hours ago.
60927+ - Activated; no logs for over 72 hours, filter missing, or Cloud SIEM index incorrectly ordered.
6091060928 x-enum-varnames:
6091160929 - INSTALL
6091260930 - ACTIVATE
@@ -60915,7 +60933,7 @@ components:
6091560933 - WARNING
6091660934 - BROKEN
6091760935 SecurityMonitoringContentPackTimestampBucket:
60918- description: Timestamp bucket indicating when logs were last collected
60936+ description: When logs were last collected through the content pack's Cloud SIEM filter or index query.
6091960937 enum:
6092060938 - not_seen
6092160939 - within_24_hours
@@ -60924,6 +60942,12 @@ components:
6092460942 - over_30d
6092560943 example: within_24_hours
6092660944 type: string
60945+ x-enum-descriptions:
60946+ - No logs observed.
60947+ - Logs received within the last 24 hours.
60948+ - Logs last seen 24 to 72 hours ago.
60949+ - Logs last seen 3 to 30 days ago.
60950+ - Logs last seen more than 30 days ago.
6092760951 x-enum-varnames:
6092860952 - NOT_SEEN
6092960953 - WITHIN_24_HOURS
@@ -62014,7 +62038,7 @@ components:
6201462038 - $ref: "#/components/schemas/SecurityMonitoringSignalRulePayload"
6201562039 - $ref: "#/components/schemas/CloudConfigurationRulePayload"
6201662040 SecurityMonitoringSKU:
62017- description: The SIEM pricing model (SKU) for the organization
62041+ description: The Cloud SIEM pricing model (SKU) for the organization.
6201862042 enum:
6201962043 - per_gb_analyzed
6202062044 - per_event_in_siem_index_2023
@@ -111561,10 +111585,7 @@ paths:
111561111585 - Security Monitoring
111562111586 /api/v2/security_monitoring/content_packs/states:
111563111587 get:
111564- description: |-
111565- Get the activation and configuration states for all security monitoring content packs.
111566- This endpoint returns status information about each content pack including activation state,
111567- integration status, and log collection status.
111588+ description: Get the activation and operational state for all Cloud SIEM content packs.
111568111589 operationId: GetContentPacksStates
111569111590 responses:
111570111591 "200":
@@ -111574,11 +111595,7 @@ paths:
111574111595 $ref: "#/components/schemas/SecurityMonitoringContentPackStatesResponse"
111575111596 description: OK
111576111597 "403":
111577- content:
111578- application/json:
111579- schema:
111580- $ref: "#/components/schemas/JSONAPIErrorResponse"
111581- description: Forbidden
111598+ $ref: "#/components/responses/NotAuthorizedResponse"
111582111599 "404":
111583111600 content:
111584111601 application/json:
@@ -111587,21 +111604,31 @@ paths:
111587111604 description: Not Found
111588111605 "429":
111589111606 $ref: "#/components/responses/TooManyRequestsResponse"
111607+ security:
111608+ - apiKeyAuth: []
111609+ appKeyAuth: []
111610+ - AuthZ:
111611+ - security_monitoring_filters_read
111590111612 summary: Get content pack states
111591111613 tags:
111592111614 - Security Monitoring
111615+ "x-permission":
111616+ operator: OR
111617+ permissions:
111618+ - security_monitoring_filters_read
111619+ - logs_read_index_data
111593111620 x-unstable: |-
111594111621 **Note**: This endpoint is in preview and is subject to change.
111595111622 If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
111596111623 /api/v2/security_monitoring/content_packs/{content_pack_id}/activate:
111597111624 put:
111598111625 description: |-
111599- Activate a security monitoring content pack. This operation configures the necessary
111626+ Activate a Cloud SIEM content pack. This operation configures the necessary
111600111627 log filters or security filters depending on the pricing model and updates the content
111601111628 pack activation state.
111602111629 operationId: ActivateContentPack
111603111630 parameters:
111604- - description: The ID of the content pack to activate.
111631+ - description: The ID of the content pack to activate (for example, `aws-cloudtrail`) .
111605111632 in: path
111606111633 name: content_pack_id
111607111634 required: true
@@ -111612,11 +111639,7 @@ paths:
111612111639 "202":
111613111640 description: Accepted
111614111641 "403":
111615- content:
111616- application/json:
111617- schema:
111618- $ref: "#/components/schemas/JSONAPIErrorResponse"
111619- description: Forbidden
111642+ $ref: "#/components/responses/NotAuthorizedResponse"
111620111643 "404":
111621111644 content:
111622111645 application/json:
@@ -111625,20 +111648,30 @@ paths:
111625111648 description: Not Found
111626111649 "429":
111627111650 $ref: "#/components/responses/TooManyRequestsResponse"
111651+ security:
111652+ - apiKeyAuth: []
111653+ appKeyAuth: []
111654+ - AuthZ:
111655+ - security_monitoring_filters_write
111628111656 summary: Activate content pack
111629111657 tags:
111630111658 - Security Monitoring
111659+ "x-permission":
111660+ operator: OR
111661+ permissions:
111662+ - security_monitoring_filters_write
111663+ - logs_modify_indexes
111631111664 x-unstable: |-
111632111665 **Note**: This endpoint is in preview and is subject to change.
111633111666 If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
111634111667 /api/v2/security_monitoring/content_packs/{content_pack_id}/deactivate:
111635111668 put:
111636111669 description: |-
111637- Deactivate a security monitoring content pack. This operation removes the content pack's
111670+ Deactivate a Cloud SIEM content pack. This operation removes the content pack's
111638111671 configuration from log filters or security filters and updates the content pack activation state.
111639111672 operationId: DeactivateContentPack
111640111673 parameters:
111641- - description: The ID of the content pack to deactivate.
111674+ - description: The ID of the content pack to deactivate (for example, `aws-cloudtrail`) .
111642111675 in: path
111643111676 name: content_pack_id
111644111677 required: true
@@ -111649,11 +111682,7 @@ paths:
111649111682 "202":
111650111683 description: Accepted
111651111684 "403":
111652- content:
111653- application/json:
111654- schema:
111655- $ref: "#/components/schemas/JSONAPIErrorResponse"
111656- description: Forbidden
111685+ $ref: "#/components/responses/NotAuthorizedResponse"
111657111686 "404":
111658111687 content:
111659111688 application/json:
@@ -111662,9 +111691,19 @@ paths:
111662111691 description: Not Found
111663111692 "429":
111664111693 $ref: "#/components/responses/TooManyRequestsResponse"
111694+ security:
111695+ - apiKeyAuth: []
111696+ appKeyAuth: []
111697+ - AuthZ:
111698+ - security_monitoring_filters_write
111665111699 summary: Deactivate content pack
111666111700 tags:
111667111701 - Security Monitoring
111702+ "x-permission":
111703+ operator: OR
111704+ permissions:
111705+ - security_monitoring_filters_write
111706+ - logs_modify_indexes
111668111707 x-unstable: |-
111669111708 **Note**: This endpoint is in preview and is subject to change.
111670111709 If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
0 commit comments