The identity and technical contract details declared by the specification.
Annotation
object
A list of annotations used in the workflow. These are like sticky notes for your workflow!
3 properties
3 required
SecurityMonitoringRuleEvaluationWindow
integer
A time window is specified to match when at least one of the cases matches true. This is a sliding window and evaluates in real time. For third party detection…
SoftwareCatalogTriggerWrapper
object
Schema for a Software Catalog-based trigger.
2 properties
1 required
SecurityMonitoringRuleTypeRead
string
The rule type.
UpdateRuleRequestData
object
Data for the request to update a scorecard rule.
2 properties
UsersType
string
Users resource type.
SecurityMonitoringRuleMaxSignalDuration
integer
A signal will "close" regardless of the query being matched once the time exceeds the maximum duration. This time is calculated from the first seen timestamp.
SecurityMonitoringRuleCaseActionOptionsUserBehaviorName
string
Used with the case action of type 'userbehavior'. The value specified in this field is applied as a risk tag to all users affected by the rule.
WorkflowDataUpdate
object
Data related to the workflow being updated.
4 properties
2 required
SecurityMonitoringRuleNewValueOptionsLearningThreshold
integer
A number of occurrences after which signals will be generated for values that weren't learned.
SecurityMonitoringRuleNewValueOptionsForgetAfter
integer
The duration in days after which a learned value is forgotten.
StartStepNames
array
A list of steps that run first after a trigger fires.
APITrigger
object
Trigger a workflow from an API request. The workflow must be published.
1 property
IncidentAttachmentAttributes
The attributes object for an attachment.
UpdateWorkflowRequest
object
A request object for updating an existing workflow.
1 property
1 required
JSONAPIErrorItem
object
API error response body
5 properties
IncidentIntegrationRelationships
object
The incident's integration relationships from a response.
2 properties
UpdateActionConnectionRequest
object
Request used to update an action connection.
1 property
1 required
OutputSchemaParametersType
string
The definition of OutputSchemaParametersType object.
RelationshipToIncidentPostmortemData
object
The postmortem relationship data.
2 properties
2 required
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property
1 required
GithubWebhookTrigger
object
Trigger a workflow from a GitHub webhook. To trigger a workflow from GitHub, you must set a webhookSecret. In your GitHub Webhook Settings, set the Payload URL…
1 property
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
UserAttributes
object
Attributes of user object returned by the API.
12 properties
IncidentPostmortemType
string
Incident postmortem resource type.
SecurityMonitoringRuleQueryAggregation
string
The aggregation type.
SecurityMonitoringRuleTypeTest
string
The rule type.
IncidentType
string
Incident resource type.
IncidentIntegrationMetadataType
string
Integration metadata resource type.
IncidentTeamUpdateAttributes
object
The incident team's attributes for an update request.
1 property
1 required
SecurityMonitoringRuleTestResponse
object
Result of the test of the rule queries.
1 property
SecurityMonitoringRuleResponse
Create a new rule.
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
StepDisplayBounds
object
The definition of StepDisplayBounds object.
2 properties
RelationshipToRuleDataObject
object
Rule relationship data.
2 properties
ActionConnectionAttributesUpdate
object
The definition of ActionConnectionAttributesUpdate object.
2 properties
SecurityMonitoringStandardRuleQuery
object
Query for matching rule.
9 properties
SecurityMonitoringFilterAction
string
The type of filtering action.
ActionConnectionAttributes
object
The definition of ActionConnectionAttributes object.
2 properties
2 required
JSONAPIErrorResponse
object
API error response.
1 property
1 required
InputSchema
object
A list of input parameters for the workflow. These can be used as dynamic runtime values in your workflow.
1 property
CaseTrigger
object
Trigger a workflow from a Case. For automatic triggering a handle must be configured and the workflow must be published.
1 property
AppTriggerWrapper
object
Schema for an App-based trigger.
2 properties
1 required
IncidentAttachmentType
string
The incident attachment resource type.
SecurityMonitoringRuleThirdPartyOptions
object
Options on third party detection method.
4 properties
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
IncidentTeamRelationships
object
The incident team's relationships.
2 properties
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
IncidentIntegrationMetadataResponseData
object
Incident integration metadata from a response.
4 properties
2 required
HTTPBody
object
The definition of HTTPBody object.
2 properties
RoleAttributes
object
Attributes of the role.
4 properties
RoleClone
object
Data for the clone role request.
2 properties
2 required
SecurityMonitoringRuleDecreaseCriticalityBasedOnEnv
boolean
If true, signals in non-production environments have a lower severity than what is defined by the rule case, which can reduce signal noise. The severity is dec…
JiraIntegrationMetadataIssuesItem
object
Item in the Jira integration metadata issue array.
5 properties
2 required
SlackIntegrationMetadata
object
Incident integration metadata for the Slack integration.
1 property
1 required
SecurityMonitoringRuleQueryPayloadData
object
Payload used to test the rule query.
5 properties
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties
2 required
IncidentServiceUpdateData
object
Incident Service payload for update requests.
4 properties
1 required
WorkflowTriggerWrapper
object
Schema for a Workflow-based trigger.
2 properties
1 required
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property
1 required
IncidentUpdateData
object
Incident data for an update request.
4 properties
2 required
User
object
User object returned by the API.
4 properties
IncidentIntegrationMetadataResponseIncludedItem
An object related to an incident integration metadata that is included in the response.
GithubWebhookTriggerWrapper
object
Schema for a GitHub webhook-based trigger.
2 properties
1 required
Trigger
One of the triggers that can start the execution of a workflow.
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties
2 required
RelationshipToUser
object
Relationship to user.
1 property
1 required
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property
1 required
UpdateWorkflowResponse
object
The response object after updating a workflow.
1 property
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties
2 required
StepDisplay
object
The definition of StepDisplay object.
1 property
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
SecurityMonitoringRuleCaseActionType
string
The action type.
IncidentServiceRelationships
object
The incident service's relationships.
2 properties
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property
1 required
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
SecurityMonitoringRuleHardcodedEvaluatorType
string
Hardcoded evaluator type.
IncidentServiceUpdateRequest
object
Update request with an incident service payload.
1 property
1 required
RelationshipToPermissionData
object
Relationship to permission object.
2 properties
RelationshipToUserData
object
Relationship to user object.
2 properties
2 required
SecurityMonitoringStandardDataSource
string
Source of events, either logs, audit trail, or Datadog events.
IncidentTeamResponseAttributes
object
The incident team's attributes from a response.
3 properties
UpdateRuleRequest
object
Request to update a scorecard rule.
1 property
IncidentIntegrationMetadataPatchData
object
Incident integration metadata data for a patch request.
2 properties
2 required
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
WorkflowDataUpdateAttributes
object
The definition of WorkflowDataUpdateAttributes object.
8 properties
HTTPIntegrationType
string
The definition of HTTPIntegrationType object.
HTTPTokenAuthUpdate
object
The definition of HTTPTokenAuthUpdate object.
5 properties
1 required
SecurityMonitoringRuleCaseActionOptions
object
Options for the rule action
2 properties
TriggerRateLimit
object
Defines a rate limit for a trigger.
2 properties
ConnectionEnvEnv
string
The definition of ConnectionEnvEnv object.
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties
2 required
HTTPIntegration
object
The definition of HTTPIntegration object.
3 properties
3 required
DatabaseMonitoringTriggerWrapper
object
Schema for a Database Monitoring-based trigger.
2 properties
1 required
RuleType
string
The JSON:API type for scorecard rules.
JiraIntegrationMetadata
object
Incident integration metadata for the Jira integration.
1 property
1 required
AnnotationDisplay
object
The definition of AnnotationDisplay object.
1 property
IncidentTeamIncludedItems
An object related to an incident team which is present in the included payload.
ActionConnectionDataType
string
The definition of ActionConnectionDataType object.
AWSCredentials
The definition of AWSCredentials object.
IncidentUserData
object
User object returned by the API.
3 properties
ScheduleTriggerWrapper
object
Schema for a Schedule-based trigger.
2 properties
1 required
IncidentResponseData
object
Incident data from a response.
4 properties
2 required
AWSAssumeRoleUpdate
object
The definition of AWSAssumeRoleUpdate object.
4 properties
1 required
AWSAssumeRoleType
string
The definition of AWSAssumeRoleType object.
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
AWSIntegration
object
The definition of AWSIntegration object.
2 properties
2 required
SecurityMonitoringRuleOptions
object
Options.
10 properties
SecurityMonitoringSignalRuleResponse
object
Rule.
18 properties
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties
2 required
IncidentServiceType
string
Incident service resource type.
SecurityMonitoringSignalRuleQuery
object
Query for matching rule on signals.
6 properties
1 required
SecurityTriggerWrapper
object
Schema for a Security-based trigger.
2 properties
1 required
IncidentUpdateRequest
object
Update request for an incident.
1 property
1 required
MSTeamsIntegrationMetadata
object
Incident integration metadata for the Microsoft Teams integration.
1 property
1 required
SecurityMonitoringRuleTestPayload
Test a rule.
SecurityMonitoringRuleQueryPayload
object
Payload to test a rule query with the expected result.
3 properties
SecurityMonitoringThirdPartyRuleCaseCreate
object
Case when a signal is generated by a third party rule.
4 properties
1 required
IncidentUserDefinedFieldType
string
The incident user defined fields type.
SecurityMonitoringReferenceTable
object
Reference tables used in the queries.
5 properties
RelationshipToRuleData
object
Relationship data for a rule.
1 property
WorkflowDataAttributes
object
The definition of WorkflowDataAttributes object.
8 properties
2 required
IncidentTrigger
object
Trigger a workflow from an Incident. For automatic triggering a handle must be configured and the workflow must be published.
1 property
ConnectionGroup
object
The definition of ConnectionGroup object.
3 properties
3 required
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties
2 required
SecurityMonitoringRuleKeepAlive
integer
Once a signal is generated, the signal will remain "open" if a case is matched at least once within this keep alive window. For third party detection method, t…
ReadinessGateThresholdType
string
The definition of ReadinessGateThresholdType object.
AnnotationMarkdownTextAnnotation
object
The definition of AnnotationMarkdownTextAnnotation object.
1 property
RoleResponse
object
Response containing information about a single role.
1 property
ActionConnectionDataUpdate
object
Data related to the connection update.
2 properties
2 required
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
RelationshipToOrganization
object
Relationship to an organization.
1 property
1 required
SelfServiceTriggerWrapper
object
Schema for a Self Service-based trigger.
2 properties
1 required
UpdateRuleResponse
object
The response from a rule update request.
1 property
OutputSchemaParameters
object
The definition of OutputSchemaParameters object.
6 properties
2 required
IncidentResponse
object
Response with an incident.
2 properties
1 required
RelationshipToIncidentPostmortem
object
A relationship reference for postmortems.
1 property
1 required
OrganizationsType
string
Organizations resource type.
SecurityMonitoringRuleSeverity
string
Severity of the Security Signal.
CaseTriggerWrapper
object
Schema for a Case-based trigger.
2 properties
1 required
SecurityTrigger
object
Trigger a workflow from a Security Signal or Finding. For automatic triggering a handle must be configured and the workflow must be published.
1 property
IncidentServiceUpdateAttributes
object
The incident service's attributes for an update request.
1 property
1 required
MonitorTrigger
object
Trigger a workflow from a Monitor. For automatic triggering a handle must be configured and the workflow must be published.
1 property
SecurityMonitoringSignalRuleResponseQuery
object
Query for matching rule on signals.
9 properties
TokenType
string
The definition of TokenType object.
AWSCredentialsUpdate
The definition of AWSCredentialsUpdate object.
WorkflowDataRelationships
object
The definition of WorkflowDataRelationships object.
2 properties
IncidentIntegrationMetadataMetadata
Incident integration metadata's metadata attribute.
ScorecardType
string
The JSON:API type for scorecard.
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property
1 required
APIErrorResponse
object
API error response.
1 property
1 required
UserResponseRelationships
object
Relationships of the user object returned by the API.
4 properties
HTTPHeaderUpdate
object
The definition of HTTPHeaderUpdate object.
3 properties
1 required
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
MSTeamsIntegrationMetadataTeamsItem
object
Item in the Microsoft Teams integration metadata teams array.
4 properties
4 required
RetryStrategyLinear
object
The definition of RetryStrategyLinear object.
2 properties
2 required
WorkflowUserRelationshipType
string
The definition of WorkflowUserRelationshipType object.
UpdateActionConnectionResponse
object
The response for an updated connection.
1 property
CloudConfigurationRegoRule
object
Rule details.
2 properties
2 required
IncidentTeamUpdateRequest
object
Update request with an incident team payload.
1 property
1 required
HTTPCredentials
The definition of HTTPCredentials object.
HTTPHeader
object
The definition of HTTPHeader object.
2 properties
2 required
CompletionCondition
object
The definition of CompletionCondition object.
3 properties
2 required
HTTPTokenAuth
object
The definition of HTTPTokenAuth object.
5 properties
1 required
CompletionConditionOperator
string
The definition of CompletionConditionOperator object.
OutputSchema
object
A list of output parameters for the workflow.
1 property
RoleResponseRelationships
object
Relationships of the role object returned by the API.
1 property
IncidentUpdateAttributes
object
The incident's attributes for an update request.
8 properties
InputSchemaParameters
object
The definition of InputSchemaParameters object.
5 properties
2 required
SecurityMonitoringRuleCaseCreate
object
Case when signal is generated.
5 properties
1 required
ConnectionEnv
object
A list of connections or connection groups used in the workflow.
3 properties
1 required
IncidentTeamResponse
object
Response with an incident team payload.
2 properties
1 required
ActionConnectionIntegrationUpdate
The definition of ActionConnectionIntegrationUpdate object.
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties
1 required
CloudConfigurationRuleComplianceSignalOptions
object
How to generate compliance signals. Useful for cloudconfiguration rules only.
4 properties
InputSchemaParametersType
string
The definition of InputSchemaParametersType object.
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
IncidentTeamUpdateData
object
Incident Team data for an update request.
4 properties
1 required
Parameter
object
The definition of Parameter object.
2 properties
2 required
IncidentRespondersType
string
The incident responders type.
WorkflowDataType
string
The definition of WorkflowDataType object.
UrlParam
object
The definition of UrlParam object.
2 properties
2 required
AWSAssumeRole
object
The definition of AWSAssumeRole object.
5 properties
3 required
RoleCloneRequest
object
Request to create a role by cloning an existing role.
1 property
1 required
IncidentServiceResponseAttributes
object
The incident service's attributes from a response.
3 properties
RelationshipToRule
object
Scorecard create rule response relationship.
1 property
SecurityMonitoringRuleImpossibleTravelOptions
object
Options on impossible travel detection method.
1 property
IncidentImpactsType
string
The incident impacts type.
RelationshipToRoleData
object
Relationship to role object.
2 properties
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties
2 required
UpdateRuleResponseData
object
The data for a rule update response.
4 properties
ActionConnectionData
object
Data related to the connection.
3 properties
2 required
SlackIntegrationMetadataChannelItem
object
Item in the Slack integration metadata channel array.
4 properties
3 required
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties
2 required
RelationshipToOrganizationData
object
Relationship to organization object.
2 properties
2 required
SecurityMonitoringRuleConvertResponse
object
Result of the convert rule request containing Terraform content.
1 property
AWSIntegrationType
string
The definition of AWSIntegrationType object.
Role
object
Role object returned by the API.
4 properties
1 required
IncidentTeamResponseData
object
Incident Team data from a response.
4 properties
CloudConfigurationComplianceRuleOptions
object
Options for cloudconfiguration rules. Fields resourceType and regoRule are mandatory when managing custom cloudconfiguration rules.
3 properties
SecurityMonitoringRuleQuery
Query for matching rule.
SecurityMonitoringRuleImpossibleTravelOptionsBaselineUserLocations
boolean
If true, signals are suppressed for the first 24 hours. In that time, Datadog learns the user's regular access locations. This can be helpful to reduce noise a…
DashboardTriggerWrapper
object
Schema for a Dashboard-based trigger.
2 properties
1 required
SecurityMonitoringThirdPartyRuleCase
object
Case when signal is generated by a third party rule.
4 properties
RelationshipToUsers
object
Relationship to users.
1 property
1 required
HTTPCredentialsUpdate
The definition of HTTPCredentialsUpdate object.
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
ActionConnectionIntegration
The definition of ActionConnectionIntegration object.
Connection
object
The definition of Connection object.
2 properties
2 required
IncidentNonDatadogCreator
object
Incident's non Datadog creator.
2 properties
ReadinessGate
object
Used to merge multiple branches into a single branch.
1 property
1 required
ChangeEventTriggerWrapper
object
Schema for a Change Event-based trigger.
2 properties
1 required
AWSIntegrationUpdate
object
The definition of AWSIntegrationUpdate object.
2 properties
1 required
OutboundEdge
object
The definition of OutboundEdge object.
2 properties
2 required
NullableRelationshipToUserData
object
Relationship to user object.
2 properties
2 required
IncidentServiceIncludedItems
An object related to an incident service which is present in the included payload.
PermissionsType
string
Permissions resource type.
APITriggerWrapper
object
Schema for an API-based trigger.
2 properties
1 required
SecurityMonitoringSignalRuleType
string
The rule type.
AnnotationDisplayBounds
object
The definition of AnnotationDisplayBounds object.
4 properties
IncidentUpdateRelationships
object
The incident's relationships for an update request.
3 properties
RuleId
string
The unique ID for a scorecard rule.
NotebookTriggerWrapper
object
Schema for a Notebook-based trigger.
2 properties
1 required
RelationshipToRoles
object
Relationship to roles.
1 property
UrlParamUpdate
object
The definition of UrlParamUpdate object.
3 properties
1 required
RelationshipToOrganizations
object
Relationship to organizations.
1 property
1 required
TokenName
string
Name for tokens.
WorkflowData
object
Data related to the workflow.
4 properties
2 required
HTTPTokenAuthType
string
The definition of HTTPTokenAuthType object.
IncidentServiceResponse
object
Response with an incident service payload.
2 properties
1 required
IncidentIntegrationMetadataResponse
object
Response with an incident integration metadata.
2 properties
1 required
SecurityMonitoringThirdPartyRootQuery
object
A query to be combined with the third party case query.
2 properties
WorkflowUserRelationship
object
The definition of WorkflowUserRelationship object.
1 property
SecurityMonitoringRuleNewValueOptionsLearningMethod
string
The learning method used to determine when signals should be generated for values that weren't learned.
SecurityMonitoringRuleCaseAction
object
Action to perform when a signal is triggered. Only available for Application Security rule type.
2 properties
WorkflowUserRelationshipData
object
The definition of WorkflowUserRelationshipData object.
2 properties
2 required
GetActionConnectionResponse
object
The response for found connection
1 property
NullableRelationshipToUser
object
Relationship to user.
1 property
1 required
IncidentTriggerWrapper
object
Schema for an Incident-based trigger.
2 properties
1 required
SecurityMonitoringRuleNewValueOptionsLearningDuration
integer
The duration in days during which values are learned, and after which signals will be generated for values that weren't learned. If set to 0, a signal will be…
SlackTriggerWrapper
object
Schema for a Slack-based trigger.
2 properties
1 required
RuleAttributes
object
Details of a rule.
9 properties
ScheduleTrigger
object
Trigger a workflow from a Schedule. The workflow must be published.
1 property
1 required
SecurityMonitoringRuleUpdatePayload
object
Update an existing rule.
14 properties
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties
2 required
RoleCloneAttributes
object
Attributes required to create a new role by cloning an existing one.
1 property
1 required
IncidentAttachmentData
object
A single incident attachment.
4 properties
4 required
RetryStrategy
object
The definition of RetryStrategy object.
2 properties
1 required
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
SecurityMonitoringRuleCase
object
Case when signal is generated.
5 properties
SecurityMonitoringRuleNewValueOptions
object
Options on new value detection method.
4 properties
HTTPTokenUpdate
object
The definition of HTTPTokenUpdate object.
4 properties
3 required
RetryStrategyKind
string
The definition of RetryStrategyKind object.
IncidentIntegrationMetadataAttributes
object
Incident integration metadata's attributes for a create request.
6 properties
2 required
SecurityMonitoringStandardRuleTestPayload
object
The payload of a rule to test
13 properties
6 required
SecurityMonitoringFilter
object
The rule's suppression filter.
2 properties
IncidentSeverity
string
The incident severity.
HTTPIntegrationUpdate
object
The definition of HTTPIntegrationUpdate object.
3 properties
1 required
ErrorHandler
object
Used to handle errors in an action.
2 properties
2 required
MonitorTriggerWrapper
object
Schema for a Monitor-based trigger.
2 properties
1 required
CompletionGate
object
Used to create conditions before running subsequent actions.
2 properties
2 required
SecurityMonitoringStandardRuleResponse
object
Rule.
24 properties
IncidentRelatedObject
string
Object related to an incident.
RolesType
string
Roles type.
IncidentServiceResponseData
object
Incident Service data from responses.
4 properties
2 required
Spec
object
The spec defines what the workflow does.
7 properties
Step
object
A Step is a sub-component of a workflow. Each Step performs an action.
9 properties
2 required
HTTPToken
object
The definition of HTTPToken object.
3 properties
3 required
SecurityMonitoringRuleDetectionMethod
string
The detection method.
RelationshipToPermissions
object
Relationship to multiple permissions objects.
1 property
IncidentTeamType
string
Incident Team resource type.
SecurityMonitoringRuleTestRequest
object
Test the rule queries of a rule (rule property is ignored when applied to an existing rule)
2 properties
IncidentIntegrationMetadataPatchRequest
object
Patch request for an incident integration metadata.
1 property
1 required
GetWorkflowResponse
object
The response object after getting a workflow.
1 property
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Datadog publishes across the network.