REST Resource: projects.locations.instances

Resource: Instance

A Instance represents an instantiation of the Instance product.

JSON representation
{
  "name": string,
  "state": enum (State)
}
Fields
name

string

Output only. The resource name of this instance. Format: projects/{project}/locations/{region}/instances/{instance}

state

enum (State)

Output only. The state of the instance.

State

The state of the instance.

Enums
STATE_UNSPECIFIED The default value.
ACTIVE The instance is active.
SOFT_DELETED The instance is soft-deleted.
SOFT_DELETE_INITIATED The instance is in the process of being soft-deleted.
UNDELETE_INITIATED The instance is in the process of being undeleted.

Methods

batchValidateWatchlistEntities

Validates a batch of entities that could be added into watchlist under an instance.

computeAllFindingsRefinementActivities

Returns findings refinement activity for all findings refinements.

countAllCuratedRuleSetDetections

Count detections across all curated rule sets.

createFeedback

RPC to submit user feedback on content generated by AI services.

extractSyslog

ExtractSyslog extracts structured part of log from a unstructured log by running a grok regex over it.

findEntity

Identifies the entity type and retrieves relevant data associated with a specified indicator.

findEntityAlerts

Get alerts for an entity

findRelatedEntities

Finds all the entities associated with provided entity.

findUdmFieldValues

Finds ingested UDM field values that match a query.

generateCollectionAgentAuth

GenerateCollectionAgentAuth generates an auth json file for the collection agent.

generateSoarAuthJwt

GenerateSoarAuthJwt signs a jwt in order to proceed with jwt exchange based authenticate with soar.

generateUdmKeyValueMappings

GenerateUDMKeyValueMappings generates key value mapping of a raw log.

generateWorkspaceConnectionToken

Generates a token that can be used to connect a workspace customer to a chronicle instance

get

Gets a Instance.

getMultitenantDirectory

Gets the super and subtenants and gets the current tenant name.

getRiskConfig

Queries the instance to get the Risk Configurations used for the computation of Entity Risk Score.

listAllFindingsRefinementDeployments

Lists all findings refinement deployments.

queryProductSourceStats

Gets available product sources along with their stats.

report

Generate a report summarizing this chronicle instance.

searchEntities

Identifies the entity type and retrieves relevant data associated with a specified indicator.

searchRawLogs

Api to get events, entities, or unparsed raw logs matching the given raw log query.

summarizeEntitiesFromQuery

Parses the query and identifies the entities contained within the search query.

summarizeEntity

Returns all entity data over specified time.

testFindingsRefinement

Tests for and returns past activity for a findings refinement, including, potentially, times when the findings refinement was not yet created.

translateUdmQuery

Translate natural language to a UDM Search query.

translateYlRule

Translate natural language to a Yara-L rule.

udmSearch

Performs a UDM search that returns matching events for the query.

updateRiskConfig

Updates RiskConfig used for the computation of Entity Risk Score.

validateQuery

Validates UDM search query by compiling the query.

verifyReferenceList

VerifyReferenceList validates list content and returns line errors, if any.

verifyRuleText

Verifies the given rule text.