Resource: Instance
A Instance represents an instantiation of the Instance product.
JSON representation |
---|
{ "name": string, "state": enum ( |
Fields | |
---|---|
name |
Output only. The resource name of this instance. Format: projects/{project}/locations/{location}/instances/{instance} |
state |
Output only. The state of the instance. |
purge_time |
Output only. The earliest time that soft-deleted tenants will be permanently deleted and will no longer be able to be undeleted. Uses RFC 3339, where generated output will always be Z-normalized and uses 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
delete_time |
Output only. The time at which the instance was soft-deleted. Uses RFC 3339, where generated output will always be Z-normalized and uses 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
wipeout_status |
Output only. The wipeout status of the instance. |
display_name |
Output only. The display name of the instance. |
secops_urls[] |
Output only. URL of the SecOps instance for the instance. https:// |
customer_code |
Output only. An acronym related to the company name. |
State
The state of the instance.
Enums | |
---|---|
STATE_UNSPECIFIED |
The default value. |
ACTIVE |
The instance is active. |
SOFT_DELETED |
The instance is soft-deleted. |
SOFT_DELETE_INITIATED |
The instance is in the process of being soft-deleted. |
UNDELETE_INITIATED |
The instance is in the process of being undeleted. |
WipeoutState
The wipeout status of the instance.
Enums | |
---|---|
WIPEOUT_STATE_UNSPECIFIED |
The default value. |
DELETE_REQUESTED |
The instance has requested deletion. |
SOFT_DELETE_IN_PROGRESS |
The instance is in the process of being soft-deleted. |
SOFT_DELETE_COMPLETED |
The instance has been soft-deleted. |
UNDELETE_REQUESTED |
The instance has requested undeletion. |
DATA_DELETION_IN_PROGRESS |
The instance is in the process of being data deleted. |
ERROR |
The instance has an error during wipeout. |
WIPED_OUT |
The instance has been wiped out. |
UNDELETE_COMPLETED |
The instance has been undeleted. |
Methods |
|
---|---|
|
Validates a batch of entities that could be added into watchlist under an instance. |
|
Returns findings refinement activity for all findings refinements. |
|
Count detections across all curated rule sets. |
|
RPC to submit user feedback on content generated by AI services. |
|
DeleteInstance deletes an Instance. |
|
ExtractSyslog extracts structured part of log from a unstructured log by running a grok regex over it. |
|
FetchFederationAccess method lists all the instances the authenticated user has access to and the operations they can perform over these instances. |
|
Identifies the entity type and retrieves relevant data associated with a specified indicator. |
|
Get alerts for an entity |
|
Finds all the entities associated with provided entity. |
|
Finds ingested UDM field values that match a query. |
|
GenerateCollectionAgentAuth generates an auth json file for the collection agent. |
|
GenerateSoarAuthJwt signs a jwt in order to proceed with jwt exchange based authenticate with soar. |
|
GenerateUDMKeyValueMappings generates key value mapping of a raw log. |
|
Generates a token that can be used to connect a workspace customer to a chronicle instance |
|
Gets a Instance. |
|
Get the BigQuery export configuration for a Chronicle instance. |
|
Gets the super and subtenants and gets the current tenant name. |
|
Queries the instance to get the Risk Configurations used for the computation of Entity Risk Score. |
|
Lists all findings refinement deployments. |
|
Gets available product sources along with their stats. |
|
Generate a report summarizing this chronicle instance. |
|
Identifies the entity type and retrieves relevant data associated with a specified indicator. |
|
Api to get events, entities, or unparsed raw logs matching the given raw log query. |
|
Parses the query and identifies the entities contained within the search query. |
|
Returns all entity data over specified time. |
|
Tests for and returns past activity for a findings refinement, including, potentially, times when the findings refinement was not yet created. |
|
Translate natural language to a UDM Search query. |
|
Translate natural language to a Yara-L rule. |
|
Performs a UDM search that returns matching events for the query. |
|
UndeleteInstance undeletes a soft-deleted Instance. |
|
Update the BigQuery export configuration for a Chronicle instance. |
|
Updates RiskConfig used for the computation of Entity Risk Score. |
|
Validates UDM search query by compiling the query. |
|
VerifyReferenceList validates list content and returns line errors, if any. |
|
Verifies the given rule text. |