@@ -100272,6 +100272,15 @@ paths:
100272100272 requestBody:
100273100273 content:
100274100274 application/json:
100275+ examples:
100276+ default:
100277+ value:
100278+ data:
100279+ attributes:
100280+ description: Queue for annotating customer support traces
100281+ name: My annotation queue
100282+ project_id: a33671aa-24fd-4dcd-9b33-a8ec7dde7751
100283+ type: queues
100275100284 schema:
100276100285 $ref: "#/components/schemas/LLMObsAnnotationQueueRequest"
100277100286 description: Create annotation queue payload.
@@ -100359,6 +100368,14 @@ paths:
100359100368 requestBody:
100360100369 content:
100361100370 application/json:
100371+ examples:
100372+ default:
100373+ value:
100374+ data:
100375+ attributes:
100376+ description: Updated description
100377+ name: Updated queue name
100378+ type: queues
100362100379 schema:
100363100380 $ref: "#/components/schemas/LLMObsAnnotationQueueUpdateRequest"
100364100381 description: Update annotation queue payload.
@@ -100464,6 +100481,15 @@ paths:
100464100481 requestBody:
100465100482 content:
100466100483 application/json:
100484+ examples:
100485+ default:
100486+ value:
100487+ data:
100488+ attributes:
100489+ interactions:
100490+ - content_id: trace-abc-123
100491+ type: trace
100492+ type: interactions
100467100493 schema:
100468100494 $ref: "#/components/schemas/LLMObsAnnotationQueueInteractionsRequest"
100469100495 description: Add interactions payload.
@@ -100519,6 +100545,15 @@ paths:
100519100545 requestBody:
100520100546 content:
100521100547 application/json:
100548+ examples:
100549+ default:
100550+ value:
100551+ data:
100552+ attributes:
100553+ interaction_ids:
100554+ - 00000000-0000-0000-0000-000000000000
100555+ - 00000000-0000-0000-0000-000000000001
100556+ type: interactions
100522100557 schema:
100523100558 $ref: "#/components/schemas/LLMObsDeleteAnnotationQueueInteractionsRequest"
100524100559 description: Delete interactions payload.
@@ -108849,6 +108884,17 @@ paths:
108849108884 requestBody:
108850108885 content:
108851108886 application/json:
108887+ examples:
108888+ default:
108889+ value:
108890+ data:
108891+ attributes:
108892+ name: Updated Personal Access Token
108893+ scopes:
108894+ - dashboards_read
108895+ - dashboards_write
108896+ id: 00112233-4455-6677-8899-aabbccddeeff
108897+ type: personal_access_tokens
108852108898 schema:
108853108899 $ref: "#/components/schemas/PersonalAccessTokenUpdateRequest"
108854108900 required: true
@@ -118148,6 +118194,37 @@ paths:
118148118194 requestBody:
118149118195 content:
118150118196 "application/json":
118197+ examples:
118198+ default:
118199+ value:
118200+ cases:
118201+ - condition: "a > 0"
118202+ name: ""
118203+ notifications: []
118204+ status: info
118205+ filters: []
118206+ hasExtendedTitle: true
118207+ isEnabled: true
118208+ message: Test rule
118209+ name: My security monitoring rule.
118210+ options:
118211+ evaluationWindow: 900
118212+ keepAlive: 3600
118213+ maxSignalDuration: 86400
118214+ queries:
118215+ - aggregation: count
118216+ distinctFields: []
118217+ groupByFields: []
118218+ metric: ""
118219+ query: "@test:true"
118220+ referenceTables:
118221+ - checkPresence: true
118222+ columnName: value
118223+ logFieldPath: testtag
118224+ ruleQueryName: a
118225+ tableName: synthetics_test_reference_table_dont_delete
118226+ tags: []
118227+ type: log_detection
118151118228 schema:
118152118229 $ref: "#/components/schemas/SecurityMonitoringRuleCreatePayload"
118153118230 required: true
@@ -118596,6 +118673,29 @@ paths:
118596118673 requestBody:
118597118674 content:
118598118675 "application/json":
118676+ examples:
118677+ default:
118678+ value:
118679+ cases:
118680+ - condition: "a > 0"
118681+ name: ""
118682+ notifications: []
118683+ status: info
118684+ filters: []
118685+ isEnabled: true
118686+ message: Test rule
118687+ name: My security monitoring rule.
118688+ options:
118689+ evaluationWindow: 900
118690+ keepAlive: 3600
118691+ maxSignalDuration: 86400
118692+ queries:
118693+ - aggregation: count
118694+ distinctFields: []
118695+ groupByFields: []
118696+ metrics: []
118697+ query: "@test:true"
118698+ tags: []
118599118699 schema:
118600118700 $ref: "#/components/schemas/SecurityMonitoringRuleUpdatePayload"
118601118701 required: true
@@ -118677,6 +118777,47 @@ paths:
118677118777 requestBody:
118678118778 content:
118679118779 "application/json":
118780+ examples:
118781+ default:
118782+ value:
118783+ rule:
118784+ cases:
118785+ - condition: "a > 0"
118786+ name: ""
118787+ notifications: []
118788+ status: info
118789+ hasExtendedTitle: true
118790+ isEnabled: true
118791+ message: My security monitoring rule message.
118792+ name: My security monitoring rule.
118793+ options:
118794+ decreaseCriticalityBasedOnEnv: false
118795+ detectionMethod: threshold
118796+ evaluationWindow: 0
118797+ keepAlive: 0
118798+ maxSignalDuration: 0
118799+ queries:
118800+ - aggregation: count
118801+ distinctFields: []
118802+ groupByFields:
118803+ - "@userIdentity.assumed_role"
118804+ name: ""
118805+ query: "source:source_here"
118806+ tags:
118807+ - "env:prod"
118808+ - "team:security"
118809+ type: log_detection
118810+ ruleQueryPayloads:
118811+ - expectedResult: true
118812+ index: 0
118813+ payload:
118814+ ddsource: source_here
118815+ ddtags: "env:staging,version:5.1"
118816+ hostname: i-012345678
118817+ message: "2019-11-19T14:37:58,995 INFO [process.name][20081] Hello World"
118818+ service: payment
118819+ userIdentity:
118820+ assumed_role: fake assumed_role
118680118821 schema:
118681118822 $ref: "#/components/schemas/SecurityMonitoringRuleTestRequest"
118682118823 required: true
@@ -119217,6 +119358,14 @@ paths:
119217119358 requestBody:
119218119359 content:
119219119360 application/json:
119361+ examples:
119362+ default:
119363+ value:
119364+ data:
119365+ attributes:
119366+ resource_ids:
119367+ - abc-123-def
119368+ type: bulk_export_resources
119220119369 schema:
119221119370 $ref: "#/components/schemas/SecurityMonitoringTerraformBulkExportRequest"
119222119371 description: The resource IDs to export.
@@ -119266,6 +119415,18 @@ paths:
119266119415 requestBody:
119267119416 content:
119268119417 application/json:
119418+ examples:
119419+ default:
119420+ value:
119421+ data:
119422+ attributes:
119423+ resource_json:
119424+ enabled: true
119425+ name: Example-Security-Monitoring
119426+ rule_query: "source:cloudtrail"
119427+ suppression_query: "env:test"
119428+ id: abc-123
119429+ type: convert_resource
119269119430 schema:
119270119431 $ref: "#/components/schemas/SecurityMonitoringTerraformConvertRequest"
119271119432 description: The resource JSON to convert.
@@ -120038,6 +120199,16 @@ paths:
120038120199 requestBody:
120039120200 content:
120040120201 application/json:
120202+ examples:
120203+ default:
120204+ value:
120205+ data:
120206+ attributes:
120207+ name: Service Account Access Token
120208+ scopes:
120209+ - dashboards_read
120210+ - dashboards_write
120211+ type: personal_access_tokens
120041120212 schema:
120042120213 $ref: "#/components/schemas/ServiceAccountAccessTokenCreateRequest"
120043120214 required: true
@@ -120150,6 +120321,17 @@ paths:
120150120321 requestBody:
120151120322 content:
120152120323 application/json:
120324+ examples:
120325+ default:
120326+ value:
120327+ data:
120328+ attributes:
120329+ name: Updated Personal Access Token
120330+ scopes:
120331+ - dashboards_read
120332+ - dashboards_write
120333+ id: 00112233-4455-6677-8899-aabbccddeeff
120334+ type: personal_access_tokens
120153120335 schema:
120154120336 $ref: "#/components/schemas/PersonalAccessTokenUpdateRequest"
120155120337 required: true
@@ -120874,6 +121056,16 @@ paths:
120874121056 requestBody:
120875121057 content:
120876121058 "application/json":
121059+ examples:
121060+ default:
121061+ value:
121062+ filter:
121063+ from: "2019-01-02T09:42:36.320Z"
121064+ query: "security:attack status:high"
121065+ to: "2019-01-03T09:42:36.320Z"
121066+ page:
121067+ limit: 25
121068+ sort: timestamp
120877121069 schema:
120878121070 $ref: "#/components/schemas/SecurityMonitoringSignalListRequest"
120879121071 required: false
@@ -120991,6 +121183,34 @@ paths:
120991121183 requestBody:
120992121184 content:
120993121185 "application/json":
121186+ examples:
121187+ default:
121188+ value:
121189+ data:
121190+ attributes:
121191+ jobDefinition:
121192+ cases:
121193+ - condition: "a > 1"
121194+ name: Condition 1
121195+ notifications: []
121196+ status: info
121197+ from: 1730387522611
121198+ index: main
121199+ message: "A large number of failed login attempts."
121200+ name: "Excessive number of failed attempts."
121201+ options:
121202+ evaluationWindow: 900
121203+ keepAlive: 3600
121204+ maxSignalDuration: 86400
121205+ queries:
121206+ - aggregation: count
121207+ distinctFields: []
121208+ groupByFields: []
121209+ query: "source:non_existing_src_weekend"
121210+ tags: []
121211+ to: 1730391122611
121212+ type: log_detection
121213+ type: historicalDetectionsJobCreate
120994121214 schema:
120995121215 $ref: "#/components/schemas/RunHistoricalJobRequest"
120996121216 required: true
@@ -121034,6 +121254,18 @@ paths:
121034121254 requestBody:
121035121255 content:
121036121256 "application/json":
121257+ examples:
121258+ default:
121259+ value:
121260+ data:
121261+ attributes:
121262+ jobResultIds:
121263+ - ""
121264+ notifications:
121265+ - ""
121266+ signalMessage: A large number of failed login attempts.
121267+ signalSeverity: critical
121268+ type: historicalDetectionsJobResultSignalConversion
121037121269 schema:
121038121270 $ref: "#/components/schemas/ConvertJobResultsToSignalsRequest"
121039121271 required: true
0 commit comments