Chronicle V1 API - Module Google::Cloud::Chronicle::V1::RuleType (v0.1.0)

Reference documentation and code samples for the Chronicle V1 API module Google::Cloud::Chronicle::V1::RuleType.

RuleType indicates the YARA-L rule type of user-created and Google Cloud Threat Intelligence (GCTI) authored rules.

Constants

RULE_TYPE_UNSPECIFIED

value: 0
The rule type is unspecified/unknown.

SINGLE_EVENT

value: 1
Rule checks for the existence of a single event.

MULTI_EVENT

value: 2
Rule checks for correlation between multiple events